← Back to home
Incidentes DFIR Forense NIST Respuesta

Incident Response Plan

May 20, 2022

Incident response framework based on NIST SP 800-61: preparation, detection, containment, eradication and recovery.

PhaseKey Actions
1. PreparationCSIRT team, SIEM, runbooks, backups
2. DetectionTriage: ps, netstat, last, find modified files
3. ContainmentIsolate system, block attacker IP, capture evidence
4. EradicationRemove malware, patch CVE, delete unauthorized accounts
5. RecoveryRestore clean backup, monitor intensively
6. Lessons LearnedPost-mortem report within 2 weeks