Security Event Triage

  1. Tools of the Triage Analyst
    1. Primary Platforms
      1. Security Information and Event Management (SIEM)
        1. Log Aggregation
          1. Alert Generation and Correlation
            1. Dashboard and Reporting
            2. Security Orchestration, Automation, and Response (SOAR)
              1. Automated Playbooks
                1. Case Management
                  1. Integration Capabilities
                  2. Extended Detection and Response (XDR)
                    1. Cross-Source Correlation
                      1. Endpoint and Network Integration
                        1. Unified Investigation Interface
                      2. Analysis and Investigation Tools
                        1. Log Management Platforms
                          1. Search and Query Capabilities
                            1. Visualization Tools
                              1. Data Retention Management
                              2. Network Protocol Analyzers
                                1. Packet Capture Analysis
                                  1. Protocol Decoding
                                    1. Traffic Flow Visualization
                                    2. Malware Sandboxes
                                      1. Automated Malware Analysis
                                        1. Behavioral Reporting
                                          1. Safe Execution Environment
                                          2. Threat Intelligence Portals
                                            1. IOC Lookup
                                              1. Threat Actor Profiles
                                                1. Campaign Tracking
                                                2. Command-Line Utilities
                                                  1. whois
                                                    1. Domain Ownership Lookup
                                                      1. Registration Information
                                                      2. nslookup and dig
                                                        1. DNS Record Querying
                                                          1. DNS Resolution Testing
                                                          2. ping and traceroute
                                                            1. Network Connectivity Testing
                                                              1. Path Analysis
                                                              2. curl and wget
                                                                1. Web Request Testing
                                                                  1. Content Retrieval
                                                                2. Vulnerability Scanners
                                                                  1. Asset Discovery
                                                                    1. Vulnerability Assessment
                                                                      1. Risk Prioritization
                                                                    2. Ticketing and Case Management Systems
                                                                      1. Incident Tracking
                                                                        1. Workflow Automation
                                                                          1. Collaboration Features
                                                                            1. Reporting and Metrics