The difference between the detections precursor and the incident
detection is the following. The detection precursors are the actions that
can lead to the actual attack. This usually is where the hackers are
searching for vulnerabilities by doing port scanning etc. This does not
mean that an incident has occurred, but that could potentially happen.
One example is when an Intrusion Detection System sends a port scan
alert. This will trigger a warning that needs to be investigated. Now with
the being said, this can lead to an incident detection indicator. The
evidence of this can be when a system starts displaying anomalies like
high CPU usage, etc.
Not long ago, I personally had to deal with a security incident. One of my
colleagues caught a hacker into one of our systems. Luckily, we were able
to stop the attack at the early stages due to the evidence we had
gathered. The indicators that led us to the incident detection were that we
noticed remote control tools installed on the server like Anywhere. Also,
when checking the antivirus logs, I was able to find many of the tools that
the hacker had attempted to use but was blocked by the antivirus. The
hacker was successful in disabling the antivirus, so I had to investigate
how that happened again. The one thing I learned is how important the
logs are. This helped put together a timeline of events.