DFIR Playbook
IR Lifecycle
Each phase of the lifecycle must be complete before the next phase can begin.
Incomplete identification can lead to incomplete containment, and incomplete investigation can cause backdoors to be left in network even after eradication.
Following this lifecycle helps to provide a structure of how to conduct Incident Response.
Host Artifacts Powershell LogsLogging is not enabled by default
Enable logging at Administrative Templates → Windows Components → Windows PowerShell