Showing posts with label DFIR. Show all posts
Showing posts with label DFIR. Show all posts
Saturday, April 22, 2017
OODA Framework for TI / DFIR / CSIR Process Engineering
THE OODA Loop (https://en.wikipedia.org/wiki/OODA_loop) can be used to develop workflows for TI / DFIR / CSIR, including leveraging TIMP implementations, like MineMeld (https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/minemeld).
Wednesday, September 14, 2016
Incident Response vs Digital Forensics
When an incident / event has happened that may turn into a full-scale breach it is best to ascertain (via a defined process / guide like 800-61) whether or not to engage in digital forensics or not.
However, beyond firing up forensic kits / tools like Sleuth / Autopsy, forensic activities may have adverse consequences as operations may be affected.
Many orgs want to be safe vs sorry, so they engage in forensics to check if there was a breach, though this may be not needed and may even be construed as impetuous.
Predicated on a quick notification on the event due to proper security education, awareness, and training (SETA); initial, cursory actions may be all that is needed. At least, initially.
However, beyond firing up forensic kits / tools like Sleuth / Autopsy, forensic activities may have adverse consequences as operations may be affected.
Many orgs want to be safe vs sorry, so they engage in forensics to check if there was a breach, though this may be not needed and may even be construed as impetuous.
Predicated on a quick notification on the event due to proper security education, awareness, and training (SETA); initial, cursory actions may be all that is needed. At least, initially.
Thursday, August 4, 2016
Opening the DFIR Community
InfraGard & SEI's CERT have long proposed & advocated for information sharing w/in the DFIR space.
With that said, will COPS (http://www.infosecurity-magazine.com/news/cops-open-incident-response/) take this InfoSec specialty to the next level? Will such actions dilute the quality DFIR SMEs work &/or wages?
TBD...
With that said, will COPS (http://www.infosecurity-magazine.com/news/cops-open-incident-response/) take this InfoSec specialty to the next level? Will such actions dilute the quality DFIR SMEs work &/or wages?
TBD...
Tuesday, July 26, 2016
UEBA & DFIR
While an obvious plug for Exabeam, this blog post nails the value-add.
Monday, July 4, 2016
Don't Forget to Plan
In the midst of the Brexit mess, we are reminded to plan before we take action.
Case in point, perform due diligence regarding information security before a merger or acquisition. Likewise, have access controls in place before a divestiture. Finally, test an incident response / disaster recovery plan before either really happens.
Regardless of one's position on Iraq 2003 or Brexit 2016, let's learn from one's inability to plan.
Case in point, perform due diligence regarding information security before a merger or acquisition. Likewise, have access controls in place before a divestiture. Finally, test an incident response / disaster recovery plan before either really happens.
Regardless of one's position on Iraq 2003 or Brexit 2016, let's learn from one's inability to plan.
Subscribe to:
Posts (Atom)