Which incident-response process step investigates an attacking host using logs in a SIEM?
Detection and analysis includes investigating indicators and incident-related data, such as SIEM log records, to validate the incident and determine the nature and scope of attacker activity. NIST incident-handling guidance identifies detection and analysis as the phase for analyzing incident-related data and determining the appropriate response.
Community Discussion