DFIR
Digital Forensics and Incident Response
operationsmedium
DFIR combines two disciplines: forensics, which reconstructs what happened from digital evidence, and incident response, which contains and remediates active attacks. DFIR practitioners image disks, analyze memory, and trace attacker actions to answer how a breach happened and what was taken, since you cannot fully recover from or learn from an incident you do not understand.