Terminology Index
Glossary
1801 terms
Showing 417-448 of 1801 terms
Containment Actions
The steps responders take to stop an incident from spreading or causing further harm, such as isolating a host, disabling an account, blocking a network connection, or revoking credentials, while preserving evidence for investigation.
Containment is the phase between detecting an incident and eradicating it, aimed at limiting damage and buying time. Actions are chosen to cut off the attacker (isolate endpoints, disable accounts, block traffic) without alerting them prematurely or destroying evidence. The right action depends on the incident and is weighed against business disruption, then confirmed effective through validation.
Introduced in: Incident Response Operations
Examples
- Isolating an infected endpoint from the network to stop spread.
- Disabling a compromised account to cut off attacker access.
- Blocking a malicious outbound connection at the firewall.
No related terms linked yet.
