The 'detection and analysis' phase of incident response includes identifying all hosts affected by an attack. This step involves analyzing the scope of the incident, determining which systems and data are impacted, and understanding the nature of the attack to inform subsequent containment and eradication efforts45. References := * CrowdStrike's overview of incident response frameworks and steps4. * VCEGuide's explanation of incident response steps