-
Notifications
You must be signed in to change notification settings - Fork 0
3. Incident use cases
brettforbes edited this page Jun 17, 2023
·
3 revisions
We want to describe classical use cases of incident investigations (blue team) from very basic to very advanced.
This is a realistic use case based on a phishing attack reported by a human. The corresponding stix bundle is here
This is a realistic use case based on a phishing attack reported by an email solution based on ML. The corresponding stix bundle is here