Incident response is nothing new. We 're all familiar with it and we 're exposed to it more and more everyday as attacks get bigger and more sophisticated. Having the right data to walk the attack backwards and be able to identify and document what happened is critical. In this session, an overview of incident detection fundamentals, the incident response process, and common questions that need to be answered during an incident, such as where we can find critical and incident-relevant data, will be addressed.