Universal triage model¶
Establish the facts¶
| Question | Establish |
|---|---|
| Who | User, account, service account, process, host, cloud identity, or role |
| What | Execution, file operation, authentication, API call, network connection, configuration, or privilege change |
| Where | Host, source, destination, account/subscription, region, or resource |
| When | First seen, last seen, frequency, and event sequence |
| How | Parent process, command line, authentication method, API, protocol, tool, or binary |
Test normality¶
Is it normal for this user, host, parent process, destination, time, geography, cloud resource, API, and privilege level?
Trigger
↓
Validate
↓
Establish context
↓
Build timeline
↓
Determine scope
↓
Pivot across telemetry
↓
Determine intent and impact
Memory aid¶
Facts before labels. Sequence before intent. Scope before closure.