RA4001: Report Incident To External Companies
Summary
ID | RA4001 |
---|---|
Brief Description | Report incident to external companies |
Author | @atc_project |
Creation Date | 2019/01/31 |
References |
|
Response Stage | Eradication |
Description
Report incident to external security companites, i.e. National Computer Security Incident Response Teams (CSIRTs). Provide all Indicators of Compromise and Indicators of Attack that have been observed.
A phishing attack could be reported to:
- National Computer Security Incident Response Teams (CSIRTs)
- U.S. government-operated website
- Anti-Phishing Working Group (APWG)
- Google Safe Browsing
- The FBI's Intenet Crime Complaint Center (IC3)
This Response Action could be automated with TheHive and MISP integration.