Incident Response: The NIST SP 800-61 Lifecycle
A blue team guide to the four phases of incident response
Apr 13, 20266 min read2
Search for a command to run...
Series
Blue team frameworks and methodologies: NIST IR lifecycle, MITRE ATT&CK, Cyber Kill Chain, Diamond Model, CTI lifecycle. The shared vocabulary every analyst needs.
A blue team guide to the four phases of incident response
The shared vocabulary for describing attacker behavior, detection engineering, and defense gaps
The six-phase CTI cycle, the four types of intelligence, and the protocols that govern sharing
Three complementary threat intel frameworks — when to use each and how they work together