Back to Learning Hub
Cybersecurity Domain 4

Incident Response (IR) & Digital Forensics

Detecting, containing, eradicating, and recovering from active cyber attacks using NIST SP 800-61 frameworks and threat hunting playbooks.

1. Overview of Incident Response

Incident Response (IR) is an organization's structured capability to quickly detect, contain, investigate, and remediate cybersecurity incidents. Rapid IR minimizes operational downtime, financial loss, data theft, and brand damage.

2. The 6-Phase Incident Response Lifecycle

[Phase 1: Preparation] -> Policies, Tools, Jump-Kits, Playbooks & Drills | [Phase 2: Identification]-> Log Correlation (SIEM), IoC Match, Triage & Scope Determination | [Phase 3: Containment] -> RAM Dump Preservation, Isolation VLAN, Account Lockout | [Phase 4: Eradication] -> Malware Removal, Vulnerability Patching, Persistence Removal | [Phase 5: Recovery] -> Clean System Rebuild, Telemetry Validation, Return to Service | [Phase 6: Lessons Learned]-> Root Cause Analysis (RCA), Post-Mortem & Playbook Updates

Detailed Phase Breakdown

3. Memory & Disk Forensics Artifacts

Digital Forensic & Incident Response (DFIR) specialists analyze specific operating system artifacts to reconstruct adversary behavior:

Windows Registry & Shimcache

Tracks executable execution history, Amcache entries, UserAssist keys, and USB device connection history.

Prefetch & Event Logs

Windows Event ID 4624 (Logon), 4625 (Failed Logon), 4688 (Process Creation), and 7045 (Service Installation).