Context Gathering
Collecting the surrounding information an analyst needs to make sense of an alert, the user, host, asset criticality, recent activity, and related events, so triage decisions rest on a full picture rather than the alert alone.
Concept Neighborhood
Start here
Benign True Positive
Where Context Gathering leads next, covered by 7 lessons.
Benign True PositiveStart here
An alert that correctly fired on the activity it was designed to detect, but where that activity turns out to be legitimate, such as an admin tool used by an authorized administrator. The detection worked; the behavior was simply expected.
7
lessons
Disposition
The decision an analyst records to close out an alert or case, classifying it as a true positive, false positive, benign true positive, or escalation. It is the formal conclusion of triage and creates an accountable record.
7
lessons
Hypothesis Formation
The analyst skill of forming a testable explanation for what an alert or anomaly might mean, then investigating to confirm or rule it out, bringing structure and direction to triage and investigation.
7
lessons
Authentication Alerts
SOC alerts triggered by login and identity events, such as failed-login bursts, impossible travel, or logins from unusual locations or devices. They are a frequent and high-value alert category because attackers often start by abusing credentials.
1
lesson
Cloud Alerts
SOC alerts generated from cloud platform activity, such as suspicious API calls, risky configuration changes, new identities or keys, and provider threat-detection findings. They require cloud-specific context to triage because the cloud control plane behaves differently from on-premises systems.
1
lesson
Cold Leads
Investigation leads that look low-priority or unlikely to be malicious based on initial assessment, which an analyst may deprioritize relative to hot leads. Judging a lead cold is a triage decision that must balance efficiency against missing a real threat.
1
lesson
Show 4 more connections
Data Access Alerts
SOC alerts triggered when data is accessed in unusual or sensitive ways, such as bulk downloads, access to restricted records, or an account reaching data it never normally touches, which can indicate theft or insider misuse.
1
lesson
Email Alerts
SOC alerts generated from email security signals, such as detected phishing, malicious attachments or links, or suspicious sender behavior, which analysts triage to catch one of the most common attack delivery channels.
1
lesson
Endpoint Alerts
SOC alerts originating from endpoint security tools like EDR and antivirus, flagging suspicious processes, malware, persistence, or anomalous host behavior. Endpoints are where much attacker activity executes, making these alerts high-value.
1
lesson
Insider Activity Alerts
SOC alerts flagging potentially malicious or risky behavior by insiders, employees or contractors, such as unusual data access, policy violations, or signs of misuse, that analysts triage with care given the human and legal sensitivity.
1
lesson
Related Lessons
7 lessons cover this conceptThe SOC Analyst Role in Depth
SOC Analyst
A Structured Methodology for Alert Triage
SOC Analyst
Investigation Deep Dive: Pivoting Through Telemetry
SOC Analyst
Documentation and Case Management
SOC Analyst
Working with Incident Response and Other Teams
SOC Analyst
Common Alert Categories and Response Playbooks
SOC Analyst
Skills, Certifications, and Career Development
SOC Analyst
Sign in to open lesson content directly.
