A little learning. A little more confidence.Your next step starts here

SOC & incident response · Lesson 6 of 6

Treat an indicator as a lead

An indicator, such as an address, domain, or file hash, can guide an investigation. A match deserves context; it is not automatically a verdict on the whole system.

SEE IT UNFOLD

A match becomes a question

Follow the sequence, or move one step at a time.

Read all 4 steps
  1. An indicator matches

    A fictional intelligence report contains an address seen in your local DNS evidence.

  2. Read the event type

    A DNS answer is not by itself a successful connection, downloaded file, or executed program.

  3. Seek corroboration

    Check time, hostname, device, process, and collection coverage. Retain conflicting evidence too.

  4. State the supported result

    Document what is known and unknown. Escalate through the playbook when the evidence and impact warrant it.

SEE THE IDEA

Keep the conclusion inside the evidence

Compare the parts before making a security decision.

  1. DNS record

    A lookup returned an address.

  2. Connection record

    A separate source may establish a network connection.

  3. Execution evidence

    Endpoint evidence is needed to support a claim that code ran.

Use a match to ask a better question. State what the evidence actually establishes.
Read the visualA DNS record contains an address listed in threat intelligence. What can you safely conclude from that alone?

The event type limits the conclusion. Additional sources and context are needed to establish subsequent activity.

Check the intelligence

Record the source, time, confidence, and what the indicator represents. Addresses can be shared or reassigned, and an old observation may no longer describe current activity.

Check the local event

Distinguish a DNS lookup from a connection and a connection from a download. Identify the affected device, process, account, and time before describing what occurred.

Test an explanation

Look for related behavior and follow the escalation playbook. ATT&CK can help describe adversary behaviors, but a technique label is not proof of attacker identity or attribution.

Put it in context

A fictional alert matches a destination address from a report published months ago. Your record shows a DNS answer, but no confirmed connection. You retain the lead, check collection coverage, and seek endpoint evidence before claiming a payload was downloaded.

Use a match to ask a better question. State what the evidence actually establishes.

Read the sources

Make it stick.

Try one short question to check your understanding and save this lesson to your progress.

YOUR LEARNING SPACE