Section 1 - Advanced Incident Response and Threat Hunting Flashcards
What is dwell time?
How long they have been in your network prior to being detected
Delta
The time between penetration and time of detection
What is the top way that a intruder is detected?
Abnormal high levels of traffic
What is organised crime motivated by?
Money
What are nation state actors (ATP) motivated by?
Information and IP theft
What does ISAC stand for?
Intelligence Sharing and Analysis Center
What are the six steps to incident response?
1) Preparation
2) Identification and Scoping
3) Containment/Intelligence Development
4) Eradication/Remediation
5) Recovery
6) Follow up/Lessons learned
What does SOC stand for?
Security Operations Center
What is the Pucker Factor?
Describing the level of stress in response to a danger
What is the difference between a Hunting Organization and a Reactive Organization?
Hunting actively looks for incidents, Reactive starts when its notified
What does IOC stand for?
Indicators of Compromise
What does IR stand for?
Incident Response
What does TTP stand for?
Tools, Tactics and Procedures
What is containment for “Active Defense”?
Data decoy, bit mangling, Adversary network segmentation, Full-scale host/Network monitoring, Kill switch
When do you use forensics vs threat hunting?
Forensics is when you don’t know anything about the enemy, Threat Hunting is when you have a signature.