A compact reference for security alert triage, evidence, vulnerability priority, incident response, hunting, and reporting.
| Need | Useful evidence |
|---|---|
| User or identity activity | Authentication, IAM, VPN, and endpoint login records |
| Host activity | EDR telemetry, process activity, file changes, and persistence artifacts |
| Network activity | Firewall, proxy, DNS, flow, IDS/IPS, and targeted capture data |
| Cloud activity | Audit trail, control-plane, storage-access, and identity events |
| Timeline | Normalized timestamps, time zones, and correlated event sequence |
Establish asset owner, criticality, exposure, segment, and data sensitivity before choosing a response. A high-confidence event on an isolated test system needs a different response from a plausible signal on an internet-facing identity service.
| Factor | Why it matters |
|---|---|
| Known exploitation or exploit availability | Raises urgency beyond severity alone |
| Internet or untrusted-network exposure | Increases likelihood and potential spread |
| Asset criticality and data | Increases business impact |
| Compensating controls | May reduce immediate risk but do not remove the finding |
| Active compromise | Requires incident handling as well as remediation |
| Owner and service objective | Establish accountability and timing |
| Phase | Objective |
|---|---|
| Preparation | Contacts, authority, logging, tools, playbooks, and exercises |
| Detection and analysis | Validate, scope, preserve evidence, and classify severity |
| Containment | Limit active harm while considering evidence and service impact |
| Eradication | Remove the cause and affected persistence or access |
| Recovery | Restore normal service, monitor, and validate clean state |
| Lessons learned | Identify root cause, gaps, ownership, metrics, and prevention actions |
Threat hunting is a proactive, hypothesis-driven search for suspicious behavior. A validated finding should improve detection, prevention, asset understanding, or response procedures.