SANS Incident Handler's Handbook and PICERL Methodology
Identification

SANS Incident Handler's Handbook and PICERL Methodology PICERL-I-04: Identification: Scope Determination

Determine the scope of compromise including affected systems, accounts, data, time window, and threat actor objectives using iterative analysis and pivoting on indicators.

Other controls in Identification

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.