SOC & incident response · Lesson 2 of 5
An alert is a starting point
An alert describes something that deserves attention. It is not, by itself, proof of an intrusion. Investigators test explanations against the available evidence.
Observation is not the same as conclusion
Fictional account: 18 failed sign-ins followed by one success.
- Observed
A sequence of failures and a successful sign-in from the same source.
- Still unknown
Whether the activity was expected, who controlled the session, and what happened next.
Read the visualIs “the entire network is compromised” supported by these observations?
No. State the observed pattern, then gather evidence that tests your explanations.
Describe the observation
Repeated authentication failures can be consistent with password guessing, but do not establish the cause alone.
Check supporting context
Review successful sign-ins, expected activity, account importance, and related events.
Separate facts from hypotheses
Write down what is observed, what is suspected, and what evidence would support or disprove it.
Put it in context
A fictional account has 18 failures, then a success from the same source. You would investigate whether the activity was expected and what happened after the successful sign-in, rather than immediately declaring either a breach or a false alarm.
Treat patterns as leads. Let additional evidence shape the conclusion.
Read the sources
Make it stick.
Try one short question to check your understanding and save this lesson to your progress.