Responding To Incidents

Run digital forensics and incident response — triage, evidence acquisition with chain of custody, host and cloud artifact analysis, timeline reconstruction, scoping, containment, eradication, and postmortem. Use during a suspected compromise, when analyzing a disk or memory image, reconstructing an attacker timeline, or answering how far an intrusion spread.

trilwu fa05194 15.2 KB Updated

File contents

trilwu/secskills/tree/main/secskills-defense/skills/responding-to-incidents commit fa05194380

Frequently asked questions

npx skillmds add trilwu/responding-to-incidents