Titre Mettre en place une collecte de données pertinente
ID RA1005
Description Usually, data collection is managed by Log Management/Security Monitoring/Threat Detection teams. You need to provide them with a list of data that is critically important for IR process. Most of the time, data like DNS and DHCP logs are not being collected, as their value for detection is relatively low. You can refer to the existing Response Actions (Preparation stage) to develop the list
Auteur your name/nickname/twitter
Creation Date DD.MM.YYYY
Catégorie General
Étapes RS0001: Préparation
Automation <ul><li>thehive/phantom/demisto/etc</li></ul>
References <ul><li>https://example.com</li></ul>

Workflow

Description of the workflow for the Response Action in markdown format.
Here newlines will be saved.