Chapter 14 - Describing Security Event Analysis Flashcards
1
Q
Name 7 Steps of Cyber Kill Chain
A
- Developed by Lockheed Martin
1. Reconnaissance
2. Weaponization
3. Delivery
4. Exploitation
5. Installation
6. Command-and-Control
7. Actions on Objectives
2
Q
Name 4 Diamond Model Nodes
A
Adversary - Threat actor responsible for threat or exploit
Capability - Tools or techniques used by the threat actor
Infrastructure - The physical or logical communication structure used to maintain and control capabilities
Victim - Adversary’s target
3
Q
Describe Chain of Custody
A
The chronological paper trail that describes the exact time each person took possession of specific evidence.