LIFARS’ CSIRT examines the results from the discussions and formulates recommendations and suggestions such as servers to install, parameters to adapt, and log settings to configure.
A member of LIFARS DFIR/CSIRT team discusses with you the availability of a central logging system or a SIEM, the level of auditing configured on your systems, the availability of a network security review, and whether indicators of compromise have been collected during or after the ransomware attack.