đ¨ Initial Trigger: Use this phase when antivirus or EDR indicates suspicious activity.
- â Verify the Alert: Confirm not False Positive. Check hash.
- â Isolate Scope: Identify infected endpoints.
- â Classify Threat: Ransomware, Trojan, or Adware?