References
Cichonski, P., Millar, T., Grance, T., & Scarfone, K. (2012). Computer security incident handling guide (NIST Special Publication 800-61, Rev. 2). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-61r2
EICAR. (n.d.). The anti-malware testfile. European Institute for Computer Antivirus Research. https://www.eicar.org/download-anti-malware-testfile/
Gartner. (n.d.-a). Security orchestration, automation and response (SOAR). In Gartner glossary. Retrieved from https://www.gartner.com/en/information-technology/glossary/security-orchestration-automation-response-soar
Gartner. (n.d.-b). Security information and event management (SIEM). In Gartner glossary. Retrieved from https://www.gartner.com/en/information-technology/glossary/security-information-and-event-management-siem
Gartner. (n.d.-c). Extended detection and response (XDR). In Gartner glossary. Retrieved from https://www.gartner.com/en/information-technology/glossary/xdr-extended-detection-and-response
Heuer, R. J. (1999). Psychology of intelligence analysis. Center for the Study of Intelligence, Central Intelligence Agency.
Joint Task Force. (2020). Security and privacy controls for information systems and organizations (NIST Special Publication 800-53, Rev. 5). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-53r5
Kent, K., Chevalier, S., Grance, T., & Dang, H. (2006). Guide to integrating forensic techniques into incident response (NIST Special Publication 800-86). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-86
Kent, K., & Souppaya, M. (2006). Guide to computer security log management (NIST Special Publication 800-92). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-92
Knerler, K., Parker, I., & Zimmerman, C. (2022). 11 strategies of a world-class cybersecurity operations center. MITRE Corporation.
Kral, P. (2011). The incident handler's handbook. SANS Institute.
Microsoft. (n.d.). Microsoft Defender Antivirus in Windows. Microsoft. https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-windows
MITRE Corporation. (n.d.-a). MITRE ATT&CK. https://attack.mitre.org/
MITRE Corporation. (n.d.-b). CALDERA. https://caldera.mitre.org/
Nelson, B., Phillips, A., & Steuart, C. (2025). Guide to computer forensics and investigations (7th ed.). Cengage.
Open Information Security Foundation. (n.d.). Suricata user guide. https://docs.suricata.io/
Proofpoint. (n.d.). Emerging Threats Open ruleset. Proofpoint. https://rules.emergingthreats.net/
Red Canary. (n.d.). Atomic Red Team. https://github.com/redcanaryco/atomic-red-team
Russinovich, M., & Garnier, T. (n.d.). Sysmon (System Monitor). Microsoft. https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon
Scarfone, K., & Mell, P. (2007). Guide to intrusion detection and prevention systems (IDPS) (NIST Special Publication 800-94). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-94
Security Onion Solutions. (n.d.). Security Onion documentation. https://docs.securityonion.net/
Wazuh, Inc. (n.d.-a). Wazuh user manual. https://documentation.wazuh.com/current/user-manual/index.html
Wazuh, Inc. (n.d.-b). Wazuh installation guide. https://documentation.wazuh.com/current/installation-guide/index.html