Distinguish between incident detection precursors and incident detection indicators
Incident detection precursors are the indications that an incident is imminent. For example,
activities at unexpected times such as traffic levels on the organization's network exceeding
the measured baseline values prove that there is a probability that an incident will occur. In
the case that systems are accessing drives, such as floppies, and CD ROMS, if the end-user is
not using them, is an indication of an incident (Crossmark). (
Incident(detection indicators on the other hand are the tools used to identify or alert the
system of an attack or incident. Some of these tools are Qualys, Nessus, Veracode. These
tools perform port scanning, communication with Command-and-Control botnet servers, high
data transfers, anomalies, and changes in the host’s behaviour. They give a detailed account
of the system showing the vulnerabilities and how long it has been since most malicious
activities can be seen in the network traffic, malware included, we can use tools to do a
forensic analysis of the traffic patterns and content (sustainability). Once the detection tool
alerts you to suspicious activity on the network, you should identify the originator of the
event and identify the device(s) responsible for the event. Most(organizations used the
MITRE ATT&CK framework to monitor threats/attackers’ behaviour, classify and study
adversary techniques and understand their intent as they work on their remediation plan.(