EDRF personas

Prev Next

To help you find the most relevant information, we have defined three personas: IT administrator, Security analyst, and Incident responder. While these may not perfectly align with your organization's structure or your specific role, they optimize content based on typical roles.

Security analyst

A security analyst defends and protects an organization against malicious threats. This involves triaging alerts to prioritize them, investigating suspicious behaviour and potential threats to determine a false positive or malicious threat, and responding to malicious threats with containment measures.

Tasks:
  • Perform search queries based on alert evidence

  • Analyze triage data and file acquisitions

  • Analyze network traffic for unusual or suspicious behavior

  • Analyze behavior from a notification, event, alert, or incident

  • Conduct third-party security reviews

  • Determine a false positive or malicious threat

  • Contain the threat

  • Create and own the investigation case

  • Coordinate remediation stakeholder efforts

  • Threat hunting for anomalies in general

  • Set up recurring searches

  • Evaluate organizational risks and threats

Incident responder

An incident responder is responsible for proactive security hardening and reactive incident management. This involves responding to escalated events and indicators from the Security Analyst and conducting in-depth investigations to determine the root cause of a breach. To continuously adapt to the threat landscape, they test and implement changes to system policies, rules, endpoint hosts, and file collection.

Tasks:
  • Test and implement new features and modifications

  • Collaborate with the IT administrator on performance and modifications to global policies

  • Collaborate with the security analyst to constantly improve controls

  • Create and tune custom IOC detection rules

  • Create APIs

  • Manage exclusions

  • Review investigation cases

  • Contain threats

  • Execute custom rules and policies

  • Remediate affected hosts

  • Modify file acquisitions

  • Apply security policies

  • Update third party threat data

  • Perform advanced configuration options

IT administrator

An IT administrator is responsible for the initial software setup, network configuration, and ongoing management of the security system. They ensure compatibility with existing IT platforms, define default settings, and manage the infrastructure for optimal performance.

Tasks:
  • Install and deploy software

  • Perform network configuration

  • Perform performance and scalability enhancements

  • Ensure compatibility with existing systems

  • Manage users

  • Set up policy configuration

  • Define data classification