DEV Community

# incidentresponse

The process of responding to and managing security incidents and breaches.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
How to investigate suspicious SSH logins without giving AI a shell

How to investigate suspicious SSH logins without giving AI a shell

Comments
4 min read
How I would use local read-only AI for first-pass server incident response

How I would use local read-only AI for first-pass server incident response

Comments
2 min read
How to triage Java memory-shell clues without unsafe default heap dumps

How to triage Java memory-shell clues without unsafe default heap dumps

Comments
3 min read
How to triage a suspected WebShell without giving AI a shell

How to triage a suspected WebShell without giving AI a shell

Comments
3 min read
What safety boundary should an AI incident investigation tool have?

What safety boundary should an AI incident investigation tool have?

Comments
3 min read
How to investigate a suspicious IP on a Linux server with read-only evidence

How to investigate a suspicious IP on a Linux server with read-only evidence

Comments
3 min read
The four-minute gap: what the Nando's machete incident reveals about incident response systems (not just training)

The four-minute gap: what the Nando's machete incident reveals about incident response systems (not just training)

Comments
4 min read
My Server's Crisis Moment: An Alert During Family Dinner

My Server's Crisis Moment: An Alert During Family Dinner

Comments
4 min read
My Own VPS Crisis: That Moment of Panic During a Client Meeting

My Own VPS Crisis: That Moment of Panic During a Client Meeting

Comments
6 min read
IRAS: Building a Production-Grade Autonomous Incident Response Agent

IRAS: Building a Production-Grade Autonomous Incident Response Agent

Comments
4 min read
The Config Rule Audit Your IR Playbook Is Missing

The Config Rule Audit Your IR Playbook Is Missing

2
Comments
3 min read
11 Months Undetected: Inside a Silent Data Exfiltration Through a Trusted Vendor's Remote-Access Tool

11 Months Undetected: Inside a Silent Data Exfiltration Through a Trusted Vendor's Remote-Access Tool

Comments
5 min read
12 practices that make on-call sustainable for small teams

12 practices that make on-call sustainable for small teams

Comments
3 min read
Post-incident reviews that actually improve things

Post-incident reviews that actually improve things

Comments
3 min read
Malware-Based Attacks: The Undying Threat of the Computer Virus

Malware-Based Attacks: The Undying Threat of the Computer Virus

Comments
5 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.