A little learning. A little more confidence.Your next step starts here

SOC Analyst · Lesson 6 of 8

Building an evidence timeline

A timeline makes a case easier to review, but only if its times and sources can be trusted. Keep original observations separate from your interpretation.

SEE THE IDEA

Keep the outcome in the timeline

Fictional records associated with session S17.

  1. 09:02 UTC
    Sign-in accepted

    Account jlee; retain the authentication event reference.

  2. 09:07 UTC
    Export requested

    The request references session S17.

  3. 09:08 UTC
    Export failed

    The recorded outcome does not show a completed export.

Matching session identifiers strengthen the connection. A request is different from a successful transfer.
Read the visualDoes the failed export prove no other data was accessed?

No. It limits the claim about this attempt. Review other relevant session activity and collection coverage.

Normalize carefully

Record original timestamps and offsets alongside a common time zone. Note missing offsets or suspected clock differences.

Link every observation

Use source and event identifiers. Keep evidence within approved storage and access rules.

Avoid causal leaps

An event occurring after another event does not prove the first caused it. Explain what ties them together, such as an account or session.

Put it in context

The sign-in is at 09:02 UTC and the export request at 09:07 UTC. Both reference session S17. A later record shows the export failed. Preserve each event and outcome.

A useful timeline shows sources, ordering, and uncertainty.

Read the sources

Make it stick.

Try one short question to check your understanding and save this lesson to your progress.

YOUR LEARNING SPACE