THREAT MITIGATION SYSTEM AND METHOD
A computer-implemented method, computer program product and computing system for: a computer-implemented method is executed on a computing device and includes: rendering a threat mitigation user interface that identifies objects within a computing platform in response to a security event; monitoring actions taken by a third-party when investigating the security event; and providing suggestions to the third-party concerning additional actions to be taken by the third-party concerning the investigation of the security event.
1 . A computer-implemented method, executed on a computing device, comprising:
rendering a threat mitigation user interface that identifies objects within a computing platform in response to a security event;
monitoring actions taken by a third-party when investigating the security event; and
providing suggestions to the third-party concerning additional actions to be taken by the third-party concerning the investigation of the security event.
2 . The computer-implemented method of claim 1 wherein monitoring actions taken by a third-party when investigating the security event include:
monitoring artifacts gathered by the third-party when investigating the security event.
3 . The computer-implemented method of claim 2 wherein the artifacts include one or more of:
raw data;
screen shots;
graphics;
notes;
annotations;
audio recordings; and
video recordings.
4 . The computer-implemented method of claim 1 wherein monitoring actions taken by a third-party when investigating the security event include:
monitoring objects reviewed by the third-party when investigating the security event.
5 . The computer-implemented method of claim 1 wherein providing suggestions to the third-party concerning additional actions to be taken by the third-party concerning the investigation of the security event includes:
providing suggestions to the third-party concerning additional objects to be reviewed by the third-party when investigating the security event.
6 . The computer-implemented method of claim 1 wherein providing suggestions to the third-party concerning additional actions to be taken by the third-party concerning the investigation of the security event includes:
providing suggestions to the third-party concerning additional artifacts to be gathered by the third-party when investigating the security event.
7 . The computer-implemented method of claim 1 wherein providing suggestions to the third-party concerning additional actions to be taken by the third-party concerning the investigation of the security event includes:
providing suggestions to the third-party concerning a remedial action to be taken by the third-party when investigating the security event.
8 . The computer-implemented method of claim 1 further comprising:
enabling the third-party to select an object within the threat mitigation user interface, thus defining a selected object; and
rendering an inspection window that defines object information concerning the selected object.
9 . The computer-implemented method of claim 8 wherein the inspection window is a popup inspection window.
10 . The computer-implemented method of claim 8 wherein the inspection window is a slide out inspection window.
11 . A computer program product residing on a computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations comprising:
rendering a threat mitigation user interface that identifies objects within a computing platform in response to a security event;
monitoring actions taken by a third-party when investigating the security event; and
providing suggestions to the third-party concerning additional actions to be taken by the third-party concerning the investigation of the security event.
12 . The computer-implemented method of claim 11 wherein monitoring actions taken by a third-party when investigating the security event include:
monitoring artifacts gathered by the third-party when investigating the security event.
13 . The computer-implemented method of claim 12 wherein the artifacts include one or more of:
raw data;
screen shots;
graphics;
notes;
annotations;
audio recordings; and
video recordings.
14 . The computer-implemented method of claim 11 wherein monitoring actions taken by a third-party when investigating the security event include:
monitoring objects reviewed by the third-party when investigating the security event.
15 . The computer-implemented method of claim 11 wherein providing suggestions to the third-party concerning additional actions to be taken by the third-party concerning the investigation of the security event includes:
providing suggestions to the third-party concerning additional objects to be reviewed by the third-party when investigating the security event.
16 . The computer-implemented method of claim 11 wherein providing suggestions to the third-party concerning additional actions to be taken by the third-party concerning the investigation of the security event includes:
providing suggestions to the third-party concerning additional artifacts to be gathered by the third-party when investigating the security event.
17 . The computer-implemented method of claim 11 wherein providing suggestions to the third-party concerning additional actions to be taken by the third-party concerning the investigation of the security event includes:
providing suggestions to the third-party concerning a remedial action to be taken by the third-party when investigating the security event.
18 . The computer-implemented method of claim 11 further comprising:
enabling the third-party to select an object within the threat mitigation user interface, thus defining a selected object; and
rendering an inspection window that defines object information concerning the selected object.
19 . The computer-implemented method of claim 18 wherein the inspection window is a popup inspection window.
20 . The computer-implemented method of claim 18 wherein the inspection window is a slide out inspection window.
21 . A computing system including a processor and memory configured to perform operations comprising:
rendering a threat mitigation user interface that identifies objects within a computing platform in response to a security event;
monitoring actions taken by a third-party when investigating the security event; and
providing suggestions to the third-party concerning additional actions to be taken by the third-party concerning the investigation of the security event.
22 . The computer-implemented method of claim 21 wherein monitoring actions taken by a third-party when investigating the security event include:
monitoring artifacts gathered by the third-party when investigating the security event.
23 . The computer-implemented method of claim 22 wherein the artifacts include one or more of:
raw data;
screen shots;
graphics;
notes;
annotations;
audio recordings; and
video recordings.
24 . The computer-implemented method of claim 21 wherein monitoring actions taken by a third-party when investigating the security event include:
monitoring objects reviewed by the third-party when investigating the security event.
25 . The computer-implemented method of claim 21 wherein providing suggestions to the third-party concerning additional actions to be taken by the third-party concerning the investigation of the security event includes:
providing suggestions to the third-party concerning additional objects to be reviewed by the third-party when investigating the security event.
26 . The computer-implemented method of claim 21 wherein providing suggestions to the third-party concerning additional actions to be taken by the third-party concerning the investigation of the security event includes:
providing suggestions to the third-party concerning additional artifacts to be gathered by the third-party when investigating the security event.
27 . The computer-implemented method of claim 21 wherein providing suggestions to the third-party concerning additional actions to be taken by the third-party concerning the investigation of the security event includes:
providing suggestions to the third-party concerning a remedial action to be taken by the third-party when investigating the security event.
28 . The computer-implemented method of claim 21 further comprising:
enabling the third-party to select an object within the threat mitigation user interface, thus defining a selected object; and
rendering an inspection window that defines object information concerning the selected object.
29 . The computer-implemented method of claim 28 wherein the inspection window is a popup inspection window.
30 . The computer-implemented method of claim 28 wherein the inspection window is a slide out inspection window.