SOC Analyst · Lesson 6 of 8
Building an evidence timeline
A timeline makes a case easier to review, but only if its times and sources can be trusted. Keep original observations separate from your interpretation.
Keep the outcome in the timeline
Fictional records associated with session S17.
- 09:02 UTCSign-in accepted
Account jlee; retain the authentication event reference.
- 09:07 UTCExport requested
The request references session S17.
- 09:08 UTCExport failed
The recorded outcome does not show a completed export.
Read the visualDoes the failed export prove no other data was accessed?
No. It limits the claim about this attempt. Review other relevant session activity and collection coverage.
Normalize carefully
Record original timestamps and offsets alongside a common time zone. Note missing offsets or suspected clock differences.
Link every observation
Use source and event identifiers. Keep evidence within approved storage and access rules.
Avoid causal leaps
An event occurring after another event does not prove the first caused it. Explain what ties them together, such as an account or session.
Put it in context
The sign-in is at 09:02 UTC and the export request at 09:07 UTC. Both reference session S17. A later record shows the export failed. Preserve each event and outcome.
A useful timeline shows sources, ordering, and uncertainty.
Read the sources
Make it stick.
Try one short question to check your understanding and save this lesson to your progress.