Establish what happened
A defensible account of the incident, with the record behind every statement.
- Investigation & analysis
- What happened, why is it risky, and how does it map to MITRE ATT&CK?
- FP/TP triage
- Real threat or false alarm — and how confident is the verdict?
- Evidence
- Which record, and which field, led to this conclusion?
- Threat intelligence
- Is this address, file or domain already known to be malicious?