1/16
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Security Event
any observale occurence on a system or network
Security Incident
an event that violates or threatens security policy and requires response
IR Lifecycle
Preparation → Detection & Analysis → Containment → Eradication → Recovery → Lessons Learned (a loop)
Containment
immediate, short-term action to stop a threat from spreading
Eradication
longer-term removal of the root cause and all malicious artifacts
Recovery
restoring systems to verified-clean, normal operation
Traige
prioritizing which alerts/incidents to work first
Severity
a rating (Critical/High/Medium/Low) of an incident’s potential harm
Asset criticality
how important an affected system is to the business
SIEM (Security Information and Event Management)
platform that centralizes and correlates logs and generates alerts
EDR (Endpoint Detection & Response)
tool providing deep endpoint visibility and response
Correlation
connecting multiple events to reveal a patterm or a story
Escalation
handing an incident up when it exceeds your scope
Chain of custody
a documented, unbroken record of how evidence was collected, handled, and stored
Blameless post-mortem
an incident review focused on fixing the system rather than assigning fault
MTTD / MTTR
mean time to detect / mean time to respond; core metrics for SOC performance
MITRE Att&CK
a shared framework of adversary tactics and techniques