Terminology Index
Glossary
1801 terms
Showing 673-704 of 1801 terms
Forensic Analysts
Blue-team specialists who investigate compromised systems in depth, collecting and analyzing evidence, disk, memory, logs, to reconstruct what an attacker did. They provide the deep analysis that supports incident response and lessons learned.
Forensic analysts focus on the detailed, evidence-driven investigation of incidents: imaging and examining disks and memory, reconstructing attacker actions from artifacts, and producing findings that hold up for response decisions and potential legal use. Within a blue team they complement incident responders and detection engineers, supplying the rigorous 'what exactly happened' that informs scoping, eradication, and post-incident learning.
Introduced in: Blue Team Operations
Examples
- Examining a disk image to reconstruct an attacker's actions on a host.
- Analyzing memory to recover evidence of what malware did.
- Producing forensic findings that guide eradication and lessons learned.
No related terms linked yet.
