Detection and Analysis¶
Deciding whether an event is an incident, how serious it is, and how far it reaches.
Why It Matters¶
Everything after this phase depends on getting it right. Contain too early with a narrow scope and the attacker keeps the access you missed; take too long and they reach their objective. Good analysis answers what happened, which systems and accounts are involved, and whether the attacker is still active.
Reference¶
Detection Sources¶
| Source | Examples |
|---|---|
| Security tooling | SIEM alerts, EDR alerts, IDS/IPS, email security |
| Identity | Risky sign-in and risky user detections, MFA anomalies |
| People | User reports, help desk tickets, IT staff noticing something odd |
| External | Vendor or customer reports, law enforcement, threat intelligence, leak site monitoring |
Analysis Steps¶
| Step | Questions |
|---|---|
| Validate | Is the alert accurate? Is the activity authorized? |
| Classify | What type of incident is it, and which playbook applies? |
| Scope | Which hosts, accounts, and data are involved? Is the attacker still active? |
| Prioritize | What severity, based on impact and how much is affected? |
| Timeline | When did it start, and what happened in what order? |
| Map | Which ATT&CK techniques were used, and what usually comes next? |
Common Early Indicators¶
| Indicator | Where to Look |
|---|---|
| Scanning from outside (remote to local) | Firewall and IDS logs: many ports or hosts from one source, HTTP to non-standard ports |
| DoS / DDoS | Traffic volume compared to baseline |
| Internal scanning (local to local) | Firewall and EDR logs; confirm whether it is an authorized vulnerability scanner |
| Failed logons | Windows Event ID 4625, Entra ID sign-in failures |
| Explicit credential use | Windows Event ID 4648 |
| Logons from unusual locations or at unusual times | Entra ID sign-in logs, VPN logs |
Write it down as you go
Record findings, evidence locations, and actions with timestamps from the first minute. Reconstructing a timeline from memory at the end of a long incident is slow and unreliable.
How I Use It¶
The first thing I do with any alert is decide whether it is real, using the matching alert triage runbook if there is one. Once it is confirmed, I pick the playbook, set a severity, and start a timeline.
Scoping is where I spend most of the time. One compromised account or infected host is rarely the whole story, so I pivot on everything I find: the attacker's IPs across all sign-ins, the malware hash across all endpoints, the phishing email across all mailboxes.
Related¶
- Alert Triage Runbooks
- Log Review Approach
- Windows Event Logs
- Evidence Handling
- Preparation, the previous phase; Containment, Eradication, and Recovery, the next