Please enable JavaScript.
Coggle requires JavaScript to display documents.
2️⃣ Phase Identification (Detecting and Confirming Security Incident) -…
2️⃣ Phase Identification (Detecting and Confirming Security Incident)
🎯 Objective of Identification
Identify that a security event has occurred
Determine whether the event is a real incident
Collect initial evidence
Understand affected systems
Assign incident severity
Start incident response documentation
📚 Important Terms
Event
Any observable activity in a system
Example:
Successful SSH login
User creation
Service restart
Alert
Notification generated by security tools
Example:
SIEM detects multiple failed SSH attempts
Incident
Confirmed security event that impacts confidentiality,
integrity, or availability
Indicator of Compromise (IOC)
Evidence that suggests attacker activity
Examples:
Malicious IP address
Suspicious file hash
Unknown user account
Malware process
TTP
Tactics Techniques and Procedures used by attackers
Evidence
Information collected for investigation
2️⃣ Enterprise Incident Identification Architecture
🖥 Linux Servers
Web Servers
Database Servers
Application Servers
Domain Servers
Cloud Linux Instances
📡 Data Collection Layer
Linux Logs
Audit Logs
Application Logs
Network Logs
Security Agent Logs
🔍 Detection Layer
SIEM
Security Information and Event Management
IDS
Intrusion Detection System
EDR
Endpoint Detection and Response
Vulnerability Scanner
👨💻 Security Analyst
Reviews alerts
Validates incidents
Collects evidence
Creates incident ticket
3️⃣ First Identification Step: Monitor Security Events
📂 Linux Log Locations
RHEL / CentOS / Rocky Linux
Main Log Directory
/var/log/
Authentication Logs
/var/log/secure
System Logs
/var/log/messages
Audit Logs
/var/log/audit/audit.log
Ubuntu / Debian
Authentication Logs
/var/log/auth.log
System Logs
/var/log/syslog
Audit Logs
/var/log/audit/audit.log
4️⃣ Identify Suspicious Authentication Activity
SSH Attack Detection
View Failed Login Attempts
RHEL
grep "Failed password" /var/log/secure
Ubuntu
grep "Failed password" /var/log/auth.log
Check Successful Login
Command
last
Check Current Users
Command
who
Command
w
5️⃣ Identify Unauthorized Users
Check Existing Users
Command
cat /etc/passwd
Check Privileged Users
Command
grep sudo /etc/group
Check Root Accounts
Command
awk -F: '$3==0 {print $1}' /etc/passwd
6️⃣ Process Identification
Objective
Find malicious running programs
View Running Processes
Commands
ps aux
top
htop
Check Network Connections
Commands
ss -tulpn
netstat -tulpn
Look For
Unknown processes
High CPU usage
Strange network connections
Processes running from /tmp
7️⃣ File Integrity Identification
Objective
Detect unauthorized file changes
Important Locations
/etc/passwd
/etc/shadow
/etc/sudoers
/usr/bin/
/usr/sbin/
/tmp/
File Checking Commands
ls -la
stat filename
sha256sum filename
find / -mtime -1
8️⃣ Log Analysis During Identification
journalctl
Linux systemd log viewer
Commands
journalctl -xe
journalctl -u sshd
journalctl --since today
9️⃣ Enterprise Security Tools Used During Identification
SIEM
Splunk
Elastic Security
IBM QRadar
EDR
CrowdStrike
SentinelOne
Microsoft Defender
IDS
Snort
Suricata
Linux Security Tools
OSSEC
AIDE
Auditd
Wazuh
Lynis
🔟 Incident Identification Workflow
Step 1
Receive Alert
Step 2
Validate Alert
Step 3
Collect Initial Evidence
Step 4
Identify Affected Host
Step 5
Determine Attack Type
Step 6
Assign Severity
Step 7
Escalate to Incident Response Team
📄 Identification Phase Documentation
Incident ID
Date and Time
Affected Server
Source IP Address
User Account
Evidence Collected
Commands Executed
Analyst Name
Severity Level