Security Alert Triage: Evidence, Scope, and Handoff
About this course
Security alerts arrive as product-specific summaries, but analysts must decide what actually happened, who or what is affected, and whether response authority should be engaged. This course teaches new and developing SOC analysts a vendor-neutral triage workflow: normalize an alert into an evidence claim, verify telemetry health, scope entities and time, test competing explanations, separate confidence from impact and urgency, select a disposition, and create a concise handoff. It aligns daily triage with current NIST incident-response guidance while preserving the boundary between an alert, a cybersecurity event, and a confirmed incident. Completion means the learner can work an unfamiliar alert methodically, avoid uncontrolled pivoting, recommend authorized action, and feed verified outcomes back into detections and data quality.
What you'll learn
- ✓ Translate an unfamiliar alert into a precise claim, required evidence, and initial safety checks.
- ✓ Verify telemetry provenance and health before using absence or presence as investigative proof.
- ✓ Scope affected entities and time with explicit pivots, stop rules, and competing hypotheses.
- ✓ Set confidence, impact, urgency, disposition, and handoff actions independently and reproducibly.
Course Content
Module 1: 1. Turn the Alert into a Testable Claim
Normalize product output into observable facts and establish whether the telemetry can support the investigation before expanding it.
An Alert Is a Claim, Not an Incident
Read detection output as a proposition about observed data, then define what would confirm, weaken, or reclassify it.
Verify Telemetry Before You Trust Presence or Absence
Check provenance, clocks, collection, parsing, suppression, retention, and action status before interpreting the alert or a missing event.
Module 2: 2. Scope and Test Explanations
Expand through explicit entity-time relationships, stop at defensible boundaries, and compare explanations using predicted and disconfirming evidence.
Scope Entities and Time with Stop Rules
Move from an anchor alert to affected accounts, devices, processes, destinations, and resources while recording why every pivot belongs.
Test Competing Hypotheses and Counter-Evidence
Compare malicious, expected, policy, and telemetry explanations through predictions rather than collecting only evidence that supports the alert.
Module 3: 3. Decide, Hand Off, and Improve
Set a disposition and response priority from calibrated confidence and impact, then produce a concise handoff and durable feedback to detections and telemetry.
Set Disposition, Severity, and Containment Authority
Make five distinct decisions: what the alert represents, how strongly evidence supports it, what could be affected, how fast to act, and who may act.
Write the Handoff and Close the Feedback Loop
Produce a compact case responders can continue, then turn verified outcomes into data, detection, playbook, and training improvements.