As you enter the detection and analysis phase of the incident handling process, what is an action you might take? running a virus scan creating a CIRT plan