Triage & Scoping
Immediate remote or on-site triage to determine the breach perimeter, identify compromised assets, and prioritise containment actions before evidence is overwritten.
Key Areas
- Remote triage within hours of engagement
- Compromised asset inventory
- Initial attacker TTP identification
- Containment priority matrix
.png&w=3840&q=75)