brencronin
Nov 4, 20257 min read
AI in Security Operation Centers (SOC)s
Standard IR Data Analysis phases A practical way to evaluate AI’s impact on incident response (IR) is by examining how it enhances the data analysis phases that analysts perform during alert triage and incident handling. These are analytical stages, distinct from the traditional IR lifecycle of Identification, Containment, Eradication, Recovery, and Lessons Learned. The core data analysis phases include: Planning, Search (including Data Collection and Parsing), Normalization,


















