H3AD-REF / REFERENCES / INCIDENT RESPONSE & ANALYSIS MODELS

One Decision Cycle Underneath Everything.
Then What You Do Inside It.

OODA Loop opens this file on purpose — it's foundational, the observe/orient/decide/act cycle every other model here is a specific instance of. NIST's IR phases, RFC 3227's order for what to image first, and malware analysis' four escalating depths are all just that cycle running during an actual incident.

PART OF A 4-FILE SERIES ON SECURITY FRAMEWORKS & MODELS Attack Lifecycle & Adversary Models · Incident Response & Analysis Models · Defensive & Hunting Maturity Models · Threat Intel Cycles

OODA Loop

Colonel John Boyd, USAF. The decision cycle underneath every other framework on this page. Whoever completes it faster relative to the other side wins the exchange.

01
OBSERVE
Raw data: alerts, telemetry, adversary indicators
›
02
ORIENT
Filter through experience and prior analysis — where bias creeps in
›
03
DECIDE
Choose a course of action from the oriented picture
›
04
ACT
Execute, then feed the result back into Observe
↻ CYCLE REPEATS — faster loops than the adversary's own OODA win the exchange

NIST 800-61 IR Lifecycle

Four phases, cyclical. Post-Incident Activity doesn't end the loop, it feeds the next Preparation phase.

01
PREPARATION
Policies, tooling, training, baselines
›
02
DETECTION & ANALYSIS
Identify, scope, and validate the incident
›
03
CONTAINMENT, ERADICATION & RECOVERY
Stop the spread, remove root cause, restore
›
04
POST-INCIDENT ACTIVITY
Lessons learned, root-cause writeup
↻ CYCLE REPEATS — Post-Incident Activity feeds back into Preparation
RELATED MODEL

SANS PICERL

A 6-step variant of the same lifecycle
SANS splits NIST's four phases into six: Preparation → Identification → Containment → Eradication → Recovery → Lessons Learned. Same cycle, finer granularity — the two get cited interchangeably, but only PICERL separates Identification from Detection & Analysis and gives Lessons Learned its own named step.

Order of Volatility

RFC 3227. Collect evidence most-volatile-first — anything below a running process is still there tomorrow; anything above it may not survive the next second.

7Archival Media
LEAST VOLATILEBackup tapes, cold storage — survives indefinitely
6Physical Configuration / Topology
STABLENetwork diagrams, wiring — changes rarely, slowly
5Remote Logging & Monitoring Data
RETAINEDSIEM, syslog — survives host compromise if shipped off-box
4Disk
PERSISTENTSurvives reboot, but can be overwritten by continued use
3Temporary File Systems
VOLATILE/tmp, swap — often gone at reboot
2Memory, Routing Table, ARP Cache, Process Table
HIGHLY VOLATILEGone the moment power drops or the process exits
PLUS #1 — REGISTERS & CPU CACHE: GONE IN NANOSECONDS, RARELY COLLECTIBLE IN PRACTICE

Malware Analysis Methodology

Sikorski & Honig, Practical Malware Analysis. Four techniques, increasing depth and effort — most analysis stops at the first two.

01
BASIC STATIC
Hashes, strings, headers — no execution
›
02
BASIC DYNAMIC
Run it in a sandbox, observe behavior
›
03
ADVANCED STATIC
Disassemble and reverse the code itself
›
04
ADVANCED DYNAMIC
Debug it live, step through execution
EACH LEVEL COSTS MORE TIME — ESCALATE ONLY AS FAR AS THE TRIAGE QUESTION REQUIRES