> For the complete documentation index, see [llms.txt](https://purplebyteone.gitbook.io/index/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://purplebyteone.gitbook.io/index/notes/education/base/purple-team/htb/htb-academy/job-role-path/soc-analyst/incident-handling-process/incident-handling.md).

# Incident Handling

An <mark style="color:green;">`event`</mark> is an action occurring in a system or network.

Examples of events are:

* A user sending an email
* A mouse click
* A firewall allowing a connection request

An <mark style="color:red;">`incident`</mark> is an event with a negative consequence.

IT security incident is an event with a clear intent to cause harm that is performed against a computer system.&#x20;

Examples of incidents are:

* Data theft
* Funds theft
* Unauthorized access to data
* Installation and usage of malware and remote access tools

{% embed url="<https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf>" %}
