> For the complete documentation index, see [llms.txt](https://purplebyteone.gitbook.io/index/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://purplebyteone.gitbook.io/index/notes/education/base/purple-team/htb/htb-academy/job-role-path/soc-analyst/incident-handling-process/incident-handling-process-overview.md).

# Incident Handling Process Overview

The `incident handling process` defines a capability for organizations to prepare, detect, and respond to malicious events.&#x20;

<div data-full-width="true"><figure><img src="https://2343629885-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtRrk9VAktaigFmSOtT8J%2Fuploads%2F5GtNZFOpnGrolqlLFdr4%2Fhandling_process.png?alt=media&amp;token=6dd1a863-eedd-4bc3-bcbb-f7d91e318b21" alt=""><figcaption><p> incident handling has two main activities, which are <code>investigating</code> and <code>recovering</code>.</p></figcaption></figure></div>

The investigation aims to:

* Discover the initial 'patient zero' victim and create an (ongoing if still active) incident timeline
* Determine what tools and malware the adversary used
* Document the compromised systems and what the adversary has done
