In this segment we are going to take a look at the Data Collection(s) portion of an incident response plan / policy. Here we will discuss the following topics:
Data Collection
Microsoft Windows Operating Systems (and how we need to collect data on these operating systems)
Linux Operating Systems (The collection of artifacts from a Linux OS)
MacOS (Collection of evidence from a MacOS / OS X system)
Linux Servers (The collection process for a linux server)
SIEM & Logging Sources (Discussing the logs, dashboards and indexes analysts can use during their investigations)
Forensic Engagement ( how we can engage forensics and when to do so. )
Video Links:
Incident Response Plan Part 1: • Creating an Incident Response Plan - Part ...
Incident Response Plan Part 2: • Creating an Incident Response Plan - Part ...
Incident Response Plan Part 3: • Creating an Incident Response Plan - Part ...
#dfir #incidentresponse #digitalforensics #socanalyst #cybersecurity