Problem
Incident response does not start with a framework. It starts with: what happened, on which host, since when, who can decide to isolate.
Scope
- triage and documentation support
- which logs and artefacts to collect first
- alert vs event vs incident
This is not a promise of around-the-clock SOC, on-site arrival, or “we evict the attacker in 15 minutes”.
Result
A note that can be used in escalation — and a list of what the data does not contain.