During the Detection and Analysis Phase of the incident response lifecycle, *security teams are notified of a possible incident and work to investigate and verify the incident by collecting and analysing data*. As a reminder, detection refers to the prompt discovery of security events and analysis involves the investigation and validation of alerts. An intrusion detection system ([[Intrusion Detection System|IDS]]) can detect possible intrusions and send out alerts to security analysts to investigate the suspicious activity. Security analysts can also use security information and event management ([[Security Information and Event Management|SIEM]]) tools to detect, collect, and analyse security data. You’ve also learned that there are *challenges with detection*. Even the best security teams can *fail to detect real threats* for a variety of reasons. For example, detection tools can only detect what security teams configure them to monitor. If they aren’t properly configured, they can fail to detect suspicious activity, leaving systems vulnerable to attack. It’s important for security teams to use additional methods of detection to increase their coverage and accuracy. - [[Threat Hunting]] - [[Threat Intelligence]] - [[Cyber Deception]]