| CPC G06F 21/554 (2013.01) [G06F 21/56 (2013.01); H04L 63/1441 (2013.01); G06F 2221/034 (2013.01)] | 30 Claims |

|
1. A computer-implemented method, executed on a computing device, comprising:
obtaining object information concerning one or more initial objects within a computing platform in response to a security event;
identifying an event type for the security event;
monitoring actions taken by a third party during an investigation of the security event, including:
monitoring artifacts gathered by the third party during the investigation of the security event; and
monitoring objects reviewed by the third party during the investigation of the security event;
executing a response script based, at least in part, upon the event type; and
providing suggestions concerning additional actions to be taken concerning investigating the security event based upon, at least in part, the gathered artifacts and the reviewed objects.
|