Real-world SOC workflows & threat handling
⬅ Back to HomeSource: Firewall Logs (FortiGate)
Indicators: Abnormal session spikes, SYN floods
Service availability restored with zero data loss.
Tool: Trellix Endpoint Security
Threat neutralized, no lateral movement.
Alert → Triage → Investigation → Containment → Eradication → RCA → Report