> For the complete documentation index, see [llms.txt](https://jacob-taylor.gitbook.io/security-analyst/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://jacob-taylor.gitbook.io/security-analyst/path-5/security-information-and-event-management/incident-handling-with-splunk.md).

# Incident Handling with Splunk

Learn to use Splunk for incident handling through interactive scenarios.

## <mark style="color:red;">Incident Handling Life Cycle</mark>

### <mark style="color:orange;">Preparation</mark>

Preparation describes the readiness of an organization against an attack by documenting requirements, defining policies, incorporating security controls, and hiring and training staff.&#x20;

### <mark style="color:orange;">Detection and Analysis</mark>

Detection engulfs everything included in detecting an incident and the analysis of the incident. This includes investigating alerts from security controls and threat hunting.

### <mark style="color:orange;">Containment, Eradication, and Recovery</mark>

Actions needed to prevent incidents from spreading and securing network(s) as well as steps to avoid an attack from spreading into a network by isolating infected host(s), clearing infection traces, and gaining back control.

### <mark style="color:orange;">Post-Incident Activity/Lessons Learned</mark>

Identifying loopholes to improve in an organization's security posture that lead to an incident.  Pinpointing weaknesses, adding detection rules, and training staff.&#x20;
