Skip to content

Latest commit

 

History

History
33 lines (21 loc) · 774 Bytes

AV_Alert.md

File metadata and controls

33 lines (21 loc) · 774 Bytes

Background

On [date], [team] received an [tool] alert of type [cat]. [tool] [action] the below file(s). [additional high level details about what occured and what acctions took place]

Findings

Source IP/Host: [ip]/[host]
MAC: [mac]
Threat: [Threat]
Signature: [sig]
FilePath: [path]
User: [user]
Action: [action]

[detailed findings of interest from investigation]

Impact

  • Unauthorized file/program could have undesired impact on enterprise.

Remediation

  • Verified user behavior which caused alert
  • Validated program and business case
  • Verified no other suspicious activity in time-frame

Recommendations

<No further actions | False-Positive | Ticket created>

Resources

  • [links or resources that validate your findings]