After the initial shock and containment efforts of a security incident, organizations enter the crucial analysis phase of the incident response lifecycle. This critical stage delves deeper, aiming to understand the nature and scope of the attack, identify the root cause, and gather crucial evidence for recovery and future prevention efforts.
What Organizations Should Do to Prepare:
- Prepare a Response Plan: Having a well-defined incident response plan in place empowers organizations to navigate the analysis phase efficiently. The plan should outline roles and responsibilities, investigation procedures, and communication protocols (Carnegie Mellon University CERT Division, 2023).
- Assemble a Response Team: A dedicated incident response team, consisting of IT security professionals, legal counsel, and public relations personnel, should be assembled to handle the various aspects of the analysis phase (SANS Institute, 2023).
- Seek External Expertise: Depending on the complexity of the incident, seeking assistance from experienced cybersecurity professionals or forensic investigators can be valuable for a comprehensive and efficient analysis (National Institute of Standards and Technology, 2020).
What to Expect During the Analysis Phase:
- Forensic Investigation: Security professionals will meticulously examine compromised systems and logs to understand the attacker’s entry point, activities within the network, and the extent of the damage caused (Cybersecurity & Infrastructure Security Agency, 2023). This may involve digital forensics techniques like data carving, memory analysis, and log analysis tools.
- Threat Identification: Analysts will work to identify the specific malware, exploit, or social engineering tactic used by the attacker. This helps determine the attack vector and potential vulnerabilities exploited, leading to informed decisions for mitigation and future patching (SANS Institute, 2023).
- Timeline Construction: Creating a detailed timeline of the incident’s progression is crucial. This timeline maps out the sequence of events, from the initial breach attempt to the discovery and containment actions taken. This information aids in understanding the attacker’s actions and identifying potential gaps in security protocols (National Institute of Standards and Technology, 2020).
- Evidence Collection: Throughout the analysis phase, it’s imperative to collect and preserve any relevant evidence, including system logs, network traffic captures, infected files, and any communication with the attacker (if applicable). This evidence serves as a vital resource for potential legal action, regulatory compliance, and future incident response efforts (Federal Bureau of Investigation, 2023).
It is important to note, this phase always seems to go really slow. This phase causes the most grief for an organization because everyone wants to be recovered as quickly as possible, but the forensics take time. You can expect at least 8 to 10 hours for each machine being analyzed often times more, 4-6 for perimeter device logs depending on the volume of logs, and a pool of time to deploy any extra tools that may need deployed. These numbers can swing higher based on any infinite number of variables in your organization. When you reach this point, and your board is frustrated, remember that slow is smooth and smooth is fast (@kevinwalsh). Use this time to start evaluating priorities, next steps, and everything done to this point. I promise you’ll get moving soon, and you’ll be armed with information that will help you get back to business faster and safer.
The forensic analysis phase is the foundation of your response. It quite literally guides you through the continued containment and soon to happen remediation phases. It informs your team to help you make the right decisions going forward and helps to ensure you are not reopening a gaping security hole that could allow a new event to trigger or a threat actor to do further damage.
References:
- Carnegie Mellon University CERT Division. (2023). Computer Emergency Response Team (CERT). https://www.sei.cmu.edu/about/divisions/cert/
- Cybersecurity & Infrastructure Security Agency. (2023). Incident Response Fundamentals. https://www.cisa.gov/topics/cybersecurity-best-practices/organizations-and-cyber-safety/cybersecurity-incident-response
- Federal Bureau of Investigation. (2023). Computer Crime Investigations Unit. https://www.fbi.gov/investigate/cyber
- National Institute of Standards and Technology. (2020). Special Publication 800-61 Revision 3: Cybersecurity Framework. https://www.nist.gov/cyberframework
- SANS Institute. (2023). Information Security Reading Room. https://www.sans.org/white-papers/454/



