~/giac-geir · Cloud Response and Analysis ▊
← GIAC Enterprise Incident Response
GIAC · objective · 10% of the exam
Cloud Response and Analysis — GIAC Enterprise Incident Response
The official GIAC documentation our Cloud Response and Analysis practice questions are cited to. Review the primary sources, then practise.
Official references for this objective
-
Sans — FOR608: Enterprise-Class Incident Response & Threat Hunting | SANS Institute
we look for suspicious user logon and email activity from the Unified Audit Logs (UAL) as a common method for detection