helpdesk
system support
system administration
incident response
product management
failing to prepare . . .
. . . prepare to fail"
where is your most important data?
definitions/keywords
roles & responsibilities
methodologies
incident response phases
engaging stakeholders
documentation standards
escalation
https://www.joshmoulin.com/digital-forensics-incident-response-forms-policies-and-procedures/
https://www.joshmoulin.com/digital-forensics-incident-response-forms-policies-and-procedures/
https://www.joshmoulin.com/digital-forensics-incident-response-forms-policies-and-procedures/
ensures nothing was missed
https://www.joshmoulin.com/digital-forensics-incident-response-forms-policies-and-procedures/
skill set has been defined
skill set integrity
prevents legal questioning
people's safety first
stay hidden (if you can)
segment & control access
determine how this happened
most volatile first
memory
network
disk
forensic hardware
forensic software
forms
additional items
lots of extra hard drives
fire safe for physical evidence
faraday cage
SANS Investigative Forensic Toolkit
https://digital-forensics.sans.org/blog/2013/02/16/idx-sample-file-malware
ensure containment worked
add preventative measures
logging
patch
etc.
after action meeting
update documentation
modify/add processes
feedback loop
preparation
detection
containment
investigation
remediation
recovery
retrospective