SERVICE / DFIR

Incident response

Triage, notes and next steps on an event — not a fake 24/7 SOC-as-a-service.

Problem

Incident response does not start with a framework. It starts with: what happened, on which host, since when, who can decide to isolate.

Scope

  • triage and documentation support
  • which logs and artefacts to collect first
  • alert vs event vs incident

This is not a promise of around-the-clock SOC, on-site arrival, or “we evict the attacker in 15 minutes”.

Result

A note that can be used in escalation — and a list of what the data does not contain.

Send inquiry