TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: How long does it take to investigate a cyber-attack?

3 点作者 ColonelBlimp超过 1 年前
Hello,<p>When companies or organisations are victims of a cyber-attack, they often claim that it will take a significant amount to time (i.e., months) to investigate and assess the impact of the incident, what parts of their systems were accessed, the type and amount of data stolen by the attackers, etc.<p>As someone with no expertise in cybersecurity I have no idea if that argument makes sense or not. I suppose that larger companies with more complex IT structures will need more time to complete an assessment compared to smaller ones. But, a technical investigation spanning months?<p>Part of the relevance of this question is because, often, the potential victims of a cyber-attack are not just the company or organisation that was breached but their employees, suppliers, customers, etc. The limited or lack of information while the investigation is being conducted might leave them &quot;out in the cold&quot; for quite a long time.<p>So, I wanted to ask you. Thanks.

1 comment

stop50超过 1 年前
1. Companies have usually more than one server 2. The servers have to be checked for backdoors. This means that every file has to be scanned against modifications and unexpected code. 3. People need to go through thousands of lines of logs to check if data has been exfiltrated and if the server was used for lateral movement.
评论 #37503241 未加载