Analysis
Summary
PDF p.301After detection, the analysis process involves investigating data to confirm if a genuine incident has occurred and determining its priority. This process may involve correlating multiple indicators and escalating complex events to senior CIRT members.
In plain words
Supplementary — not from your PDFAnalysis decides whether the event is a real incident (true positive) or not (false positive), and how serious it is. Impact is judged by data integrity, downtime, economic and publicity cost, scope, detection time and recovery time. Categorizing incidents (using threat intelligence and the Cyber Kill Chain) gives a shared language, and playbooks, data-driven SOPs for specific scenarios, guide each step.
Detailed explanation
PDF p.301Incident Verification
- True Positive: Confirmed incident based on multiple indicators.
- False Positive: Dismissed report if no genuine incident is found.
- Escalation: Complex or high-impact events may be escalated to senior CIRT members.
Impact Assessment
- Data Integrity: Value of data at risk.
- Downtime: Degree of disruption to business processes.
- Economic/Publicity Impact: Short-term costs (incident response, lost business) and long-term costs (reputation damage).
- Scope: Number of systems affected, not always indicative of priority.
- Detection Time: Speed of detecting breaches.
- Recovery Time: Length of remediation process.
Incident Categorization
- Purpose: Ensures shared understanding among response team members.
- Threat Intelligence: Provides insights into adversary tactics, techniques, and procedures (TTPs).
- Cyber Kill Chain: Framework describing attack stages, useful for threat research.
Playbooks
- Purpose: Guides investigators in determining priorities and remediation plans.
- Content: Data-driven SOPs for specific cyber threat scenarios.
- Process: Starts with an alert report and leads through analysis, containment, eradication, recovery, and lessons learned.
Important terms
taken from the text above- True Positive
- Confirmed incident based on multiple indicators.
- False Positive
- Dismissed report if no genuine incident is found.
- Escalation
- Complex or high-impact events may be escalated to senior CIRT members.
- Data Integrity
- Value of data at risk.
- Downtime
- Degree of disruption to business processes.
- Economic/Publicity Impact
- Short-term costs (incident response, lost business) and long-term costs (reputation damage).
- Detection Time
- Speed of detecting breaches.
- Recovery Time
- Length of remediation process.
- Threat Intelligence
- Provides insights into adversary tactics, techniques, and procedures (TTPs).
- Cyber Kill Chain
- Framework describing attack stages, useful for threat research.
Examples & real-world scenarios
Supplementary — not from your PDF- Correlating a phishing report with a suspicious login to confirm an incident.
- Escalating a possible data breach to senior CIRT members.
- Following a ransomware playbook.
Scenario
Two incidents arrive together: 100 PCs with adware, and one database server with signs of data theft. Impact on data and the business makes the single server the higher priority, even though fewer systems are affected.
Common mistakes
Supplementary — not from your PDF- Prioritizing by number of affected systems alone.
- Not documenting why a report was dismissed as a false positive.
Practical skills
Supplementary — not from your PDF- Prioritize incidents using impact factors.
What I should remember
Key Points PDF p.301-
Incident Verification
- True Positive: Confirmed incident.
- False Positive: Dismissed report.
- Escalation: For complex events.
-
Impact Assessment
- Data Integrity: Value of data.
- Downtime: Business disruption.
- Economic/Publicity Impact: Short-term and long-term costs.
- Scope: Number of systems affected.
- Detection Time: Speed of detection.
- Recovery Time: Length of remediation.
-
Incident Categorization
- Purpose: Shared understanding.
- Threat Intelligence: Insights into TTPs.
- Cyber Kill Chain: Attack stages framework.
-
Playbooks
- Purpose: Guides for incident response.
- Content: SOPs for threat scenarios.
- Process: Steps from alert to lessons learned.