Investigation Expansion
Broadening an investigation as new leads emerge, following indicators and behaviors to additional systems, accounts, and activity, so the full scope of an incident is uncovered rather than just the initial alert.
Concept Neighborhood
Start here
Alert Triage
The foundation Investigation Expansion builds on, worth understanding first.
Alert TriageStart here
The first analytical step after an alert fires: quickly assessing what it is, whether it is a real threat or a false positive, and how urgent it is, so the right ones move into deeper investigation.
12
lessons
Indicator Pivoting
An analyst investigation skill of moving from one indicator to related ones, an IP to the domains it hosts, a hash to where else it appears, to expand an investigation and uncover the full scope of activity.
3
lessons
Analyst Development
6
lessons
IR Execution
6
lessons
Behavioral Pivoting
3
lessons
Cross-Source Correlation
3
lessons
Pivoting
3
lessons
Investigation Scope
1
lesson
Show 1 more connection
Related Lessons
6 lessons cover this conceptValidate the Alert and Open the Case
SOC Analyst
Expand Scope and Declare the Incident
SOC Analyst
Coordinate and Verify Containment
SOC Analyst
Preserve Evidence and Assess Sensitive-Data Impact
SOC Analyst
Hunt for Residual Activity and Repair Detection Gaps
SOC Analyst
Recover, Communicate, Measure, and Learn
SOC Analyst
Sign in to open lesson content directly.
