Incident Response in follows clear stages. The order matters: acting too early may alert the attacker and destroy evidence.
Process stages
- Preparation — backups, centralized logs () and a plan prepared in advance.
- Identification — detecting the incident via anomalous Event IDs and EDR alerts.
- Containment — isolating infected computers and blocking compromised accounts.
- Eradication — removing Persistence, resetting passwords and keys.
- Recovery — restoring services to operation and increased monitoring.
- Lessons Learned — documentation and tightening defenses.