Talk With an Expert

Incident Handling Preparation: Learning Normal with the Kansa PowerShell Incident Response Framework

Incident Handling Preparation: Learning Normal with the Kansa PowerShell Incident Response Framework (PDF, 2.19MB)Published: 22 Aug, 2016
Created by
Jason Simsay

Preparation is a critical step in establishing an effective incident response program. Information Security professionals that will be called upon to handle an incident must prepare ahead of time. Kansa is a PowerShell Incident Response Framework developed by Dave Hull. The PowerShell Remoting feature is leveraged to establish a highly scalable and extensible system state collection platform. Once data is collected from across the Microsoft environment, an extensive set of frequency analysis scripts may be executed to enable incident handlers to turn unknowns into knowns and to discover anomalies and indicators of compromise.