Cyber defenders, what do you do after an alert?
So you’re an infosec /cyber defender and you get an alert via an IDS or on your SIEM system, what are some of the things you’d do next or want to know?
For example, I get an alert and see an unfamiliar IP address or URL in the log/event. What should I do next? What should I look for? Where?
Thanks in advance for your insights.