Topic: Incident Response, Monitoring, and Governance
๐จ Incident Response Steps
Know the NIST process:
- Preparation
- Identification
- Containment
- Eradication
- Recovery
- Lessons Learned
๐งช Indicators of Compromise (IOCs)
Examples:
- Unknown processes
- Unusual outbound traffic
- Unexpected admin accounts
- File changes
- Log anomalies
๐ Security Monitoring Tools