TrustedSec Incident Response Team Slack AMA 02.17.2021
ID: db2bbead-f822-5a0a-ac9b-2053491c0156
STIX ID: report--db2bbead-f822-5a0a-ac9b-2053491c0156
Feed Name: TrustedSec blog
This TrustedSec AMA transcript summarizes practitioner advice and community questions on incident response topics — including cloud VM memory capture, forensic tools (WinPmem, Volatility/Rekall, NirSoft, Eric Zimmerman), log aggregation strategies (Sysmon, Winlogbeat, ELK/Splunk), evidence handling, use of legal counsel, EDR value, and onboarding new IR hires. The conversation focuses on operational best practices, automation considerations, and trade-offs rather than reporting any active compromise or adversary activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
