CIRT Technical Manual

Search file hashes. MD5. SHA1. Search for network contacts. URLs. Domains. IP Addresses. Submit sample(s) to Palo Alto WildFire sandbox. Record any payload file hashes, contacted URLS/Domains/IP Addresses. IF AFFECTING > 10 SYSTEMS OR SYSTEMS HOSTING SENSITIVE DATA: Capture network packet data moving to/from infected computer using Tap or Span. ................
................