Cyber Defense Center | Incident Response & Threat Monitoring

Incident Response & Threat Monitoring

Proactive defense • Structured IRP • Real-time threat detection • Cyber resilience

Incident Response Plan (IRP)

PREPARE • DETECT • CONTAIN • ERADICATE • RECOVER

A structured approach to handle security breaches, minimize damage, restore operations, and maintain compliance (GDPR, HIPAA, etc.).

Why IRP matters:
✅ Speed of response → reduce downtime
✅ Minimized impact → limit data loss
✅ Legal compliance → avoid penalties
✅ Reputation protection → trust

Threat Monitoring Essentials

24/7 visibility • anomaly detection • threat hunting
  • SIEM – centralized log aggregation (Splunk, QRadar)
  • EDR / XDR – endpoint telemetry & response (CrowdStrike, SentinelOne)
  • Network Monitoring (NTA) – detect C2 traffic, data exfiltration
  • Threat Intelligence Feeds – known IOCs, TTPs (MITRE ATT&CK)
  • User Behavior Analytics (UBA) – unusual access patterns
Real-time alert sample: “Multiple failed logins + privilege escalation → possible ransomware”

Key Components of IRP

  • Roles & responsibilities – Incident Commander, IT forensics, Legal, PR
  • Playbooks for ransomware, phishing, insider threats
  • Containment strategies – network isolation, account revocation
  • Eradication methods – remove malware, patch CVEs, reset credentials
  • Recovery procedures – system restore, business continuity
  • Post-mortem & improvement – update IRP after each incident
Splunk QRadar CrowdStrike Volatility

Threat Hunting & Monitoring Sources

  • DNS logs – detect beaconing / DGA domains
  • Proxy & firewall logs – unusual outbound connections
  • Endpoint process creation – detect LOLBins / ransomware execution
  • Authentication logs – brute force, impossible travel
  • File integrity monitoring (FIM) – unauthorized changes
  • Cloud audit trails – suspicious API calls (AWS CloudTrail, Azure Monitor)
MITRE ATT&CK mapping example: T1059 (Command & Scripting) → monitor powershell.exe flags.

Who to Notify in an Incident

  • 🔸 Internal: management, IT security, legal, communications
  • 🔸 External: affected customers, regulatory bodies (GDPR/SEC), law enforcement (CISA/FBI)
  • 🔸 Third-party vendors: if their systems are implicated
  • 🔸 Cyber insurance – timely reporting may be required

Best Practices for IR & Monitoring

  • 🔹 Establish baseline for normal behavior
  • 🔹 Automate alerts with SIEM correlation rules
  • 🔹 Regular tabletop exercises (simulated ransomware attack)
  • 🔹 Continuous training for SOC/IRT teams
  • 🔹 Backup critical data (3-2-1 rule)
  • 🔹 Focus on containment first — stop the spread before deep forensics
“If you can stand, don’t sit – if you can walk, don’t lie still” – agility defeats attackers.

Recommended IR & Monitoring Toolstack

SIEM: Splunk / QRadar EDR: CrowdStrike / Defender NTA: Darktrace / Zeek Vulnerability: Nessus / Qualys Forensics: FTK Imager, Velociraptor Threat Intel: Recorded Future
🛡️ Post-incident review: always update your playbook. Log everything, test annually.
Cyber Defense Framework | NIST SP 800-61 aligned • Proactive monitoring saves billions.