FIR (Fast Incident Response) – Cyber Security Tool
FIR (Fast Incident Response) – Cyber Security Incident Management Platform
- Information about the tool!!
FIR (Fast Incident Response) is a cybersecurity incident management platform designed for agility and speed. It allows for easy creation, tracking, and reporting of cybersecurity incidents.
FIR is for anyone needing to track cybersecurity incidents (CSIRTs, CERTs, SOCs, etc.). It’s was tailored to suit our needs and our team’s habits, but we put a great deal of effort into making it as generic as possible before releasing it so that other teams around the world may also use it and customize it as they see fit.
Features:
- Subject: a short description of your incident. The one that will appear on event tables.
- Business Lines: entities concerned by this incident. You choose what you make of business lines: internal department, customers, etc.
- Category: Category of the incident (ex: phishing, malware). Categories are also customizable in the admin panel.
- Status: can take three values: Open, Closed and Blocked. These are all labels defined in the admin panel
- Detection: how the incident was detected. Default values: CERT, External, Poleand Group. These values can be changed in the admin panel in the labels section
- Severity: from 1 to 4.
- Date / Time: date and time of the incident
- Is an incident: differentiates between an event and an incident
- Description: free-form text describing the event
Incident response cyber can reduce damage, improve recovery time, and mitigate losses after a security incident.
ReplyDelete