Security Watch

Sunday, November 23, 2008

Incident Response References

Tips for examining a suspect server to decide whether to escalate for formal incident response

Incident Questionnaire for Responders

Windows Intrusion Discovery

Linux Intrusion Discovery: 1, 2

Building Incident Response Plan

Incident Calcification mindmap

Incident Handling and Response - 147 Resources

What not to do when reporting an incident

Security Incident Rating

The big picture of security incident cycle

ENISA Practice Guide for Incident Management

ENISA, A step by step approach on how to setup a CSIRT

NIST 800-61, Incident Handling Guide

RFC 2350, Expectations for Computer Security Incident Response


Tools:
Clearinghouse for Incident Handling Tools

Orion Live CD:
Based on BackTrack4, with additional case tracking and collaboration tools, in addition to some network analysis tools that might be helpful for network forensics. More info here.

SANS Investigative Forensic Toolkit (SIFT) Workstation

Helix

0 comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments (Atom)

About Me

My Photo
OkamalO
I am a Security Analyst, with more than 12 years in network security operations, architecture, design and incident handling. Email: osama AT okamalo DOT com twitter: okamalo
View my complete profile

Subscribe To

Posts
Atom
Posts
Comments
Atom
Comments

My Blog List

  • SANS Internet Storm Center, InfoCON: green
    ISC StormCast for Monday, February 13th 2012 http://isc.sans.edu/podcastdetail.html?id=2320, (Mon, Feb 13th)
    15 hours ago
  • Didier Stevens
    Quickpost: Disassociating the Key From a TrueCrypt System Disk
    3 days ago
  • Dancho Danchev's Blog - Mind Streams of Information Security Knowledge
    Summarizing Webroot's Threat Blog Posts for January
    1 week ago
  • extraexploit
    the last/final touch!
    2 weeks ago
  • CIP VIGILANCE
    SCADA Security Evaporates in Texas
    2 months ago

Search This Blog

Loading...

Blog Archive

  • Feb (1)
  • Jan (1)
  • Dec (1)
  • Nov (2)
  • Oct (6)
  • Sep (2)
  • Aug (6)
  • Jul (3)
  • Jun (5)
  • May (7)
  • Apr (6)
  • Mar (9)
  • Feb (8)
  • Jan (8)
  • Dec (12)
  • Nov (9)
  • Oct (18)
  • Sep (17)
  • Aug (11)
  • Jul (6)
  • Jun (15)
  • May (12)
  • Apr (12)
  • Mar (9)
  • Feb (12)
  • Jan (16)
  • Dec (10)
  • Nov (9)

Twitter Updates

Awesome Inc. template. Template images by mammuth. Powered by Blogger.