logo

TrustedSec Incident Response Team Slack AMA 02.17.2021

ID: db2bbead-f822-5a0a-ac9b-2053491c0156

STIX ID: report--db2bbead-f822-5a0a-ac9b-2053491c0156

Feed Name: TrustedSec blog

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This TrustedSec AMA transcript summarizes practitioner advice and community questions on incident response topics — including cloud VM memory capture, forensic tools (WinPmem, Volatility/Rekall, NirSoft, Eric Zimmerman), log aggregation strategies (Sysmon, Winlogbeat, ELK/Splunk), evidence handling, use of legal counsel, EDR value, and onboarding new IR hires. The conversation focuses on operational best practices, automation considerations, and trade-offs rather than reporting any active compromise or adversary activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.