In this section

Incident Triage and First Response: Course Orientation

1-2 hours · Module 0
A first responder in the first minutes of an incident: a countdown clock at the left, evidence being triaged across identity, endpoint, cloud, and network panels, and a single containment decision pending and highlighted in orange
INCIDENT TRIAGE AND FIRST RESPONSE · MODULE 00
An alert just landed. The next hour decides the outcome.
When an alert lands you have minutes, not hours, and your first moves shape everything that follows. Is this real? How bad? Who needs to act? What evidence vanishes if I wait? Act too slowly and the attacker reaches their objective before you've classified the alert. Act too fast on the wrong call and you wipe volatile evidence or pull a production system offline over a false positive. Triage is the discipline of that first hour, and this course teaches it as a method that holds across identity, endpoint, cloud, and network, on any stack, so you classify, preserve, contain, and escalate correctly under pressure. This module sets what triage is, where it stops, and how the course gets you there.
11 modules
the first hour, mastered
Identity-first
tokens, sessions, OAuth
Any stack
Microsoft, Splunk, Linux
All levels
every concept built up

Why this course exists

An alert lands and the clock starts. Before any full investigation, someone has to make the fast first calls: is this real, how bad is it, who needs to act, and what evidence will be gone if they wait. That is triage, and the first hour is where incidents are won or lost. Get the calls right and you contain the threat while it's small. Get them wrong in either direction and it costs you: move too slowly and the attacker finishes the job before you've even classified the alert, move too fast on a bad read and you tip the attacker off, destroy the volatile evidence you needed, or take down production over a false positive.

The hard part was never the tooling. It is making correct decisions under time pressure with incomplete information, and knowing where triage stops and investigation begins. That is what this course builds. It teaches triage as a discipline, the method that decides the first hour, and then drills that method across every environment a modern incident touches: identity, endpoint, cloud, and network. The tools are where you execute the method, never the subject.

Your options close as the clock runs minute 0 minute 60 full options few, costly contain quietly, preserve, watch Triage is the discipline of spending that first hour well, before the window narrows to a few expensive moves.

What you will be able to do

This course is built around the calls you can make in the first hour, not the tools you can name. Every module drills the triage method against the evidence a real incident leaves behind.

Preserve what's volatile first
Know what evidence disappears, and in what order, and capture it before triage destroys it.
Triage identity fast
Make the identity-first, token-aware moves modern attacks demand: tokens, sessions, credentials, and OAuth and SaaS abuse.
Triage any environment
Run the same method across endpoint, cloud and hybrid, and network and perimeter, changing the source, not the discipline.
Follow a multi-environment attack
Triage an intrusion as it crosses identity, endpoint, cloud, and network, keeping one coherent picture.
Classify, escalate, contain
Set severity correctly, escalate to the right people, and make the containment call under pressure with the cost in view.
Triage with AI, then prove it
Use automation without outsourcing judgment, then run a full multi-environment triage end to end in the capstone.

You also leave with things you keep: the three instruments the course drills into habit, the triage scorecard, the five-query pack, and the triage report, plus the full multi-environment triage you run in the capstone, all built to lift straight into your own work.

From where you start to where you finish An alert lands and you freeze: too slow or wrong Preserve, then triage identity Triage any environment Classify, escalate, contain You run the first hour with speed and a defensible call

One method, any stack

Triage is a cross-platform discipline, and this course treats it that way. Its "environment" is not a single product, it is a method you can run anywhere. You teach the method as a question first and a query second: every triage move starts from a fixed question, and the same question gets answered in the cloud, on Windows, and on Linux. The source and the syntax change. The method and the artifact you produce do not.

One triage question fanning out to three environment panels, Cloud, Windows, and Linux, each using a different data source and query, all converging on one identical triage artifact accented in orange: the source and query change per environment, the method and artifact stay constant

You run it against a concrete, free-to-build default lab so you can execute every query yourself. The lab is Microsoft-anchored with free and open alternatives paired throughout, and you can start cloud-only in about thirty minutes. That default is deliberate, not a limitation: most of the audience, in-house SOC, consultants, and MSSP analysts, works in Microsoft-heavy environments, so the lab is both buildable at no cost and applicable to real work. It does not make this a Microsoft course. The three-tab query blocks mean a student who finishes TR can triage in Splunk or on a bare Linux box, not just in the default stack. The transferable skill is the point.

How the course is built

Eleven modules move from the first-hour problem through to a full multi-environment triage you run yourself.

FOUNDATIONS Modules 0 to 1 The triage problem, the 60-minute window, evidence volatility and preservation, and your reference lab IDENTITY-FIRST TRIAGE Modules 2 to 3 Tokens, sessions, and credentials, then OAuth and SaaS: the moves modern attacks start with ENVIRONMENT TRIAGE Modules 4 to 6 Endpoint, cloud and hybrid, and network and perimeter: the same method across each DECISION AND RESPONSE Modules 7 to 10 Multi-environment attack triage, severity classification and escalation, containment decisions, and triage in the age of AI and automation CAPSTONE Module 11: a full multi-environment triage, end to end REFERENCE Triage runcards and further reading

What you need and who this is for

There are no prerequisites, and every concept is explained the first time it appears. This is an all-levels course: if you're new, it builds the discipline in front of you; if you're experienced, the you-already-know framing lets you skip to the moves you don't have yet. It's for anyone who is first to an alert: in-house SOC analysts, consultants, MSSP analysts, and incident responders who own the critical first hour.

A free, swappable lab
Microsoft-anchored with free and open alternatives paired throughout, buildable at no cost, with a cloud-only start in about thirty minutes so you can run every query yourself.
A transferable, cross-platform method
Question first, query second. The three-tab blocks show the same triage answered in cloud, Windows, and Linux, so the method carries to Splunk or a bare Linux box, not just the default stack.
How to get the most
Run each move in your own lab and fill in the scorecard and report as you go. The instruments you build are what you'll reach for during a real first hour.

Do I already know this material?

Six quick scenarios across the full range of this course, from the first-hour basics to its hardest calls. Answer them to find out where you sit, and whether this course fits or it will sharpen knowledge you already have.

An alert fires on a live Windows host that may still be actively exfiltrating. You have capture tooling ready and time for one action before escalation. What do you do first?

Isolate the host from the network immediately to stop possible exfiltration.
Capture volatile data, memory, active connections, and running processes, with your ready tooling, then isolate.
Memory, live connections, and running processes are the most perishable evidence, and both network isolation and killing a process alter or destroy them. With capture ready in seconds you preserve volatile state first, then isolate. Order of volatility decides the first move.
Pull a full disk image first for preservation.
Kill the suspicious process to stop the activity.

You have confirmed one compromised account and revoked its sessions. You notice the same source touched two other accounts, but you have not confirmed compromise there. The clock is running. What is the right triage action?

Hand off to investigation now; analysing multiple accounts is investigation's job.
Keep going and fully reconstruct the attacker's entry vector across all three accounts.
Close the contained account and raise the other two as separate alerts.
Quickly check the other two accounts for the same indicators, contain any that are confirmed, then hand off with the full scope.
Triage owns the immediate blast radius, not just the first alert. With an active scoping signal you confirm and contain the immediate spread before handing off. Handing off too early loses the live scope; full reconstruction is investigation's job; splitting them into separate alerts breaks the correlation.

You have contained a compromised cloud account: reset the password, revoked active sessions, and required re-MFA. A day earlier the attacker had consented an OAuth application to that account. Are you done containing the identity?

No; the OAuth application's consent grant retains its own access through the tokens it was issued, independent of the user's password and sessions, so you must revoke the app grant.
A consented application holds access independent of the user's credentials and sessions, so resetting the password and revoking sessions never touches it. Containing the identity means revoking the application consent too. That is the token-aware reflex.
Yes; password reset, session revocation, and re-MFA cover it.
No; you must also disable the account entirely.
Yes, once you reset the password a second time to be sure.

A process on a server beacons to an external address every sixty seconds. It is signed by a known vendor, runs from its expected install path, and threat intel has no hits on the address. What is the most appropriate triage conclusion?

Benign; it is vendor-signed, runs from the expected path, and intel is clean.
Malicious; regular sixty-second beaconing is a command-and-control signature.
You cannot conclude yet; confirm the parent process, the command line, and whether this beaconing is expected for that binary on that host before clearing it.
Signed and well-located is not a clearance: legitimate binaries get side-loaded and lived off, and plenty of benign software beacons. The discriminating check is the process lineage, command line, and expected behaviour on that host. Resisting the looks-clean reflex is the skill.
Benign; vendor-signed binaries cannot be misused.

In fifteen minutes you see two things: an executive account with a risky sign-in, then an OAuth consent, then a new forwarding rule; and a separate burst of failed logins against forty service accounts from one address. You can escalate only one as critical right now. Which, and why?

The forty failed service-account logins; the volume is far higher.
The executive sequence; a risky sign-in, then a consent grant, then a forwarding rule is a coherent chain indicating account takeover and data access in progress, while the service-account burst is so far unsuccessful authentication.
Severity follows confirmed impact trajectory, not raw volume. Forty failed logins are loud but show no access; the executive sequence shows a takeover with data access underway. Under a single-escalation constraint, the in-progress compromise wins.
Both equally; raise two criticals at once.
Neither yet; gather more evidence before escalating either.

An attacker has a confirmed foothold on a customer-facing server during business hours, and you have evidence they are moving laterally toward a domain controller. Full isolation will tip them off, and they may hold a second foothold you have not found. What is the defensible call?

Isolate the compromised server now and watch for activity elsewhere, accepting that you may tip the attacker off, because preventing domain controller compromise outweighs stealth and the service cost.
When the trajectory is toward a domain controller, decisive containment beats stealth: the cost of DC compromise dwarfs a tip-off or service downtime. Staying quiet to hunt a second foothold risks the worst outcome, taking the whole segment down is disproportionate and may still miss it, and leaving the live foothold online does not stop the lateral path.
Keep monitoring quietly to find the suspected second foothold first, to avoid alerting the attacker.
Take the entire network segment offline to be certain.
Reset the domain admin credentials and leave the host online.
This course is for you.
You will build the first-hour method from the ground up: the order of volatility, the identity-first reflex, reading process and cloud evidence, and the containment call, all on evidence you work through yourself.
Start Incident Triage and First Response
You have the fundamentals. The value here is the harder half.
You are solid on the basics, so the payoff is the back half: triaging a multi-environment attack, setting severity as a shape, making containment decisions under pressure, and triage in the age of AI and automation.
Start with the advanced modules
You clearly know your way around triage.
You handled the multi-environment correlation and the containment call under uncertainty, the senior end of the discipline. Take the course to sharpen what you already have, close the gaps you did not expect, and turn strong instincts into a method you can run and defend under pressure.
Start Incident Triage and First Response

Start here

You are a student of this course now, so start by deciding what you want from it. Are you here to run the first hour with confidence instead of freezing, to build a repeatable triage method you can defend, or to get faster at triaging environments you don't see every day? Name that outcome, then turn it into a study plan: which environments you most need to be quick in, how much time you'll give it each week, and what you want to be able to do in the first hour by the time you finish.

The rest of Module 0 sets you up to do exactly that. Work through it to see the triage problem and why the first hour decides the outcome, where triage ends and investigation begins, how the course teaches the method, your reference environment and how to build the lab, and the instruments you'll use throughout. Then begin Module 1.