<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>I Told You So, Volume 1 - playbooks</title>
    <subtitle>Archive, Volume 1: conference talks and papers on security and risk, 2010 to 2018.</subtitle>
    <link rel="self" type="application/atom+xml" href="https://blog.itys.net/vol1/tags/playbooks/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2011-10-19T00:00:00+00:00</updated>
    <id>https://blog.itys.net/vol1/tags/playbooks/atom.xml</id>
    <entry xml:lang="en">
        <title>Incident Handling, Forensics and Hacking Techniques</title>
        <published>2011-10-19T00:00:00+00:00</published>
        <updated>2011-10-19T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/incident-handling-mncia/"/>
        <id>https://blog.itys.net/vol1/posts/incident-handling-mncia/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/incident-handling-mncia/">&lt;p&gt;The SANS Incident Handling &amp;amp; Forensics presentation by Matthew J. Harmon
provides a comprehensive overview of how organizations should prepare for,
respond to, and learn from security incidents. Drawing on industry best
practices and real-world examples, it emphasizes the importance of structured
processes, clear communication, and rigorous evidence handling to minimize
damage and restore operations promptly.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;incident-response&quot;&gt;Incident Response&lt;&#x2F;h2&gt;
&lt;p&gt;First, the talk lays out the six core phases of incident response: Preparation,
Identification, Containment, Eradication, Recovery, and Lessons Learneddetailing
the goals and key actions at each stage. Core principles such as work in pairs,
maintain a strict chain of custody, never operate on original data, and enforce
a need-to-know policy are reinforced throughout. These guidelines ensure that
responders act methodically, take comprehensive notes, and prevent further
compromise while preserving forensic integrity.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;techniques-and-toolkits&quot;&gt;Techniques and Toolkits&lt;&#x2F;h2&gt;
&lt;p&gt;Second, the presentation transitions to practical techniques and toolkits. It
introduces the SANS Investigative Forensic Toolkit (SIFT) and offensive-focused
distributions like BackTrack for evidence acquisition and analysis. Step-by-step
procedures cover documenting the scene, identifying and preserving data sources
(from servers and workstations to mobile devices), performing bit-by-bit
imaging, and analyzing logs and memory. Finally, it underscores the need to
produce clear, audience-appropriate reportswhether for corporate management,
legal teams, or law enforcementto drive improvements and policy changes
post-incident.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;55853_2011-10-19_Incident_Handling_Forensics_and_Hacking_Techniques-MNCIA.pdf&quot;&gt;Minnesota High Tech Crime Investigators
Association&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
</feed>
