Reactive
Incident Response
Execution of response actions to an already confirmed cyber incident, including detection and analysis, containment, eradication, recovery, and post-incident stage activities.
Incident Inspection
Execution of triage and initial analysis to confirm or deny the existence of a cyber incident.
Digital Forensics
Collection and analysis of forensic evidence relating to a cyber incident.
Malware Analysis
Analysis of malware to determine its behaviour and capabilities.