SOC & incident response · Lesson 6 of 6
Treat an indicator as a lead
An indicator, such as an address, domain, or file hash, can guide an investigation. A match deserves context; it is not automatically a verdict on the whole system.
A match becomes a question
Follow the sequence, or move one step at a time.
Reduced motion is on. Use Next step to explore without animation.
Read all 4 steps
- An indicator matches
A fictional intelligence report contains an address seen in your local DNS evidence.
- Read the event type
A DNS answer is not by itself a successful connection, downloaded file, or executed program.
- Seek corroboration
Check time, hostname, device, process, and collection coverage. Retain conflicting evidence too.
- State the supported result
Document what is known and unknown. Escalate through the playbook when the evidence and impact warrant it.
Keep the conclusion inside the evidence
Compare the parts before making a security decision.
- DNS record
A lookup returned an address.
- Connection record
A separate source may establish a network connection.
- Execution evidence
Endpoint evidence is needed to support a claim that code ran.
Read the visualA DNS record contains an address listed in threat intelligence. What can you safely conclude from that alone?
The event type limits the conclusion. Additional sources and context are needed to establish subsequent activity.
Check the intelligence
Record the source, time, confidence, and what the indicator represents. Addresses can be shared or reassigned, and an old observation may no longer describe current activity.
Check the local event
Distinguish a DNS lookup from a connection and a connection from a download. Identify the affected device, process, account, and time before describing what occurred.
Test an explanation
Look for related behavior and follow the escalation playbook. ATT&CK can help describe adversary behaviors, but a technique label is not proof of attacker identity or attribution.
Put it in context
A fictional alert matches a destination address from a report published months ago. Your record shows a DNS answer, but no confirmed connection. You retain the lead, check collection coverage, and seek endpoint evidence before claiming a payload was downloaded.
Use a match to ask a better question. State what the evidence actually establishes.
Read the sources
Make it stick.
Try one short question to check your understanding and save this lesson to your progress.