Module 9: Incident Response Case Management
Creating and Managing Incident Cases
Following Along
Just a section for starting the VM group.
Introducing IRIS for Case Management














Adding Assets







Creating a Timeline













Adding Evidence
Email evidence in lab scenario:







Communicating and Collaborating











Generating a Report









Closing a Case and Case Retention





Becoming the root user on the IRIS server
IRIS case database backup step
Creating a Case Based on Our Lab Incident
Creating a Case For Our Incident
Do it all again for the lab.
Adding Our Compromised and Investigated Assets
Do it all again for the lab.
Creating a Timeline Based on What We Know
Do it all again for the lab.
Adding Evidence from Our Investigation
Do it all again for the lab.
PreviousModule 8: Digital Forensics for Incident RespondersNextModule 10: Active Incident Containment
Last updated