Cyber Security Tools Flashcards
Antivirus software
A software program used to prevent, detect, and eliminate malware and viruses
Security information and event management (SIEM)
An application that collects and analyzes log data to monitor critical activities in an organization
Splunk
`A data analysis platform
Chronicle
is a cloud-native SIEM tool that stores security data for search and analysis. Cloud-native means that Chronicle allows for fast delivery of new features.
Network protocol analyzer (packet sniffer)
A tool designed to capture and analyze data traffic within a network
chain of custody playbook
process of documenting evidence possession and control during an incident lifecycle
protecting and preserving evidence playbook
properly working with fragile and volatile digital evidence
order of volatility
a sequence outlining the order of data that must be preserved from first to last