Study guide
Technical reference and lesson notes
Triage answers a focused question: does this incident represent activity that warrants deeper response?
Start with the reason the incident exists
Review the analytics rule, alert evidence, impacted entities, and timeline before jumping directly into remediation. This establishes what was observed and what assumptions still need validation.
Correlate instead of guessing
Related sign-ins, process events, endpoint alerts, and identity activity can change the severity of an event. Use investigation queries to test a hypothesis rather than collecting unrelated telemetry.
- Identify the affected user, host, IP, or resource.
- Determine whether the behavior is expected for that entity.
- Look for expansion in time, scope, or technique.
- Record why the incident was closed or escalated.
Good closure is evidence-based
A benign conclusion should explain the evidence that supports it, not simply state that no issue was found.