Incident Response (IR) & Digital Forensics
Detecting, containing, eradicating, and recovering from active cyber attacks using NIST SP 800-61 frameworks and threat hunting playbooks.
1. Overview of Incident Response
Incident Response (IR) is an organization's structured capability to quickly detect, contain, investigate, and remediate cybersecurity incidents. Rapid IR minimizes operational downtime, financial loss, data theft, and brand damage.
2. The 6-Phase Incident Response Lifecycle
Detailed Phase Breakdown
- Preparation: Provisioning forensic workstations (Volatility, KAPE, Autopsy), establishing out-of-band communication channels, and defining IR playbooks for Ransomware, Phishing, and BEC.
- Identification: Triaging alerts triggered by EDR/SIEM, extracting Indicators of Compromise (hashes, IPs, domain C2s), and establishing the attack timeline.
- Containment: Preserving volatile RAM memory (using WinPmem or FTK Imager) prior to isolating the compromised host from the network.
- Eradication: Removing scheduled tasks, malicious services, registry run keys, and compromised Kerberos tickets.
- Recovery: Restoring gold-master OS images, deploying fresh SSH keys/passwords, and continuously auditing system logs.
- Lessons Learned: Holding a formal post-incident review within 72 hours and delivering executive/regulatory breach notifications.
3. Memory & Disk Forensics Artifacts
Digital Forensic & Incident Response (DFIR) specialists analyze specific operating system artifacts to reconstruct adversary behavior:
Windows Registry & Shimcache
Tracks executable execution history, Amcache entries, UserAssist keys, and USB device connection history.
Prefetch & Event Logs
Windows Event ID 4624 (Logon), 4625 (Failed Logon), 4688 (Process Creation), and 7045 (Service Installation).