image
CHAPTER  4
Getting the Investigation Started on the Right Foot
For Fools rush in where Angels fear to tread.
—Alexander Pope
image
When an event is detected, we’ve seen that many organizations tend to transition directly to an investigation. In some cases, the details of the event may justify a quick jump to investigate. In most cases, however, we believe that an extra step is needed to get the investigation started on the right foot. We’ve seen many investigations that start prior to confirmation of basic facts. They often suffer from a lack of focus ...

Get Incident Response & Computer Forensics, Third Edition, 3rd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.