Incident Triage and First Response

Read the record. Make the call. Hand it on.

Make the first hour's calls from the records, not the alert. Confirm what fired, capture what expires, scope and score the incident, contain it in an order that removes the access, and hand it off with a report the next team can act on.

Included with Premium, from $19.99/month, or $179/year and save 25%. Preview the first module free, no account needed.
View Pricing Download Lab Pack Take End of Course Exam → 40 CPE Credits

What you'll be able to do

✓Confirm or dismiss an alert from the records behind it, in five queries that run on any SIEM
✓Capture the evidence that expires first, in an order that holds against the clock
✓Scope an incident by the entities it shares, and group alerts into incidents on links rather than resemblance
✓Score severity and priority on a scorecard you can defend, and apply the overrides that must change it
✓Triage account compromise, phishing and BEC, malware and ransomware, and exfiltration and intrusion, each to a call with its severity
✓Contain in an order that removes the access, weighing what containment destroys and what it alerts the attacker to
✓Escalate, test the notification clock, and hand off a Triage Report and package the next team can start from
What students say about this course

“Coming from an admin background, the incident triage course forced me to think a little when things are hitting the fan. Appreciate the platform and what you guys are trying to do. So far, it's worth my subscription.”

Jamie
FOR301 | Premium tier | 13 modules across 4 phases | 40 CPE credits

Course Syllabus

Every module and every lesson. The first three modules are open; the rest open on a click.

Download the full syllabus (PDF)

Phase 1: Foundations

Module 0Course OrientationCourse Preview

Incident Triage and First Response: the first hour of an incident as five decisions, taught against a month of records from an attacked company. What the course covers, how it is built, where to practice, and a six-scenario check of whether it fits you.

Show 6 lessonsHide lessons
  1. 0.10.1 Incident Triage and the First HourPreview
  2. 0.20.2 Triage and Incident Response: The Handoff PointPreview
  3. 0.30.3 The Triage ClockPreview
  4. 0.40.4 Your Lab Environment and EquivalentsPreview
  5. 0.50.5 Building the Triage Lab: Steps and CostsPreview
  6. 0.60.6 Triage Tools: Scorecard, Query Pack and Triage ReportPreview
Module 1Alert Triage and Validation

What an alert claims, how to test the claim against the evidence underneath it, and how to classify the result as a true positive, a false positive, benign activity, or unresolved, across identity, endpoint, email, cloud and network alerts.

Show 9 lessonsHide lessons
  1. 1.11.1 Anatomy of a Security Alert
  2. 1.21.2 True Positives, False Positives and Benign Activity
  3. 1.31.3 Detection Rules Behind an Alert
  4. 1.41.4 The Five-Query Triage Pack
  5. 1.51.5 First Look: Sign-In and Identity Alerts
  6. 1.61.6 First Look: Endpoint Alerts
  7. 1.71.7 First Look: Email and Cloud Alerts
  8. 1.81.8 First Look: Network Alerts
  9. 1.9Module Summary and Knowledge Check
Module 3Incident Scope and Blast Radius

What an incident includes and what it can reach: scope built from links rather than the alert queue, pivots taken to completion, the blast radius of accounts, machines and data, alerts grouped on shared entities, a sourced triage timeline, and every claim graded by the evidence that carries it.

Show 9 lessonsHide lessons
  1. 3.13.1 Incident Scope: Users, Hosts and Time
  2. 3.23.2 Pivoting on Users, Hosts and IP Addresses
  3. 3.33.3 Blast Radius: Accounts and Access
  4. 3.43.4 Blast Radius: Endpoints and Lateral Reach
  5. 3.53.5 Blast Radius: Applications and Data
  6. 3.63.6 Related Alerts and Incident Grouping
  7. 3.73.7 The Triage Timeline
  8. 3.83.8 Scope Confidence and Its Limits
  9. 3.9Module Summary and Knowledge Check
Module 4Incident Severity and Prioritization

How bad an incident is and how fast it must be acted on, scored from evidence on an eight-question card, turned into a priority tier and a response clock, with overrides for the features a total cannot capture and a record for the cases where the card runs out.

Show 9 lessonsHide lessons
  1. 4.14.1 Severity and Urgency
  2. 4.24.2 The Triage Scorecard: Eight Questions
  3. 4.34.3 The Triage Scorecard: Scoring From Evidence
  4. 4.44.4 The Triage Scorecard: Unanswered Questions
  5. 4.54.5 Priority Tiers and Response Timelines
  6. 4.64.6 Severity Overrides
  7. 4.74.7 Prioritization With Conflicting Evidence
  8. 4.84.8 Scorecard Limits and Analyst Judgment
  9. 4.9Module Summary and Knowledge Check

Phase 2: Incident Triage

Module 5Account Compromise Triage

Triaging a compromised account from its evidence: suspicious sign-ins, stolen sessions, MFA fatigue, password spray and brute force, service accounts, the changes attackers make to keep access, and hybrid pivots, each ending in a call, a severity and a next move.

Show 9 lessonsHide lessons
  1. 5.15.1 Suspicious Sign-Ins: Location, Device and Risk
  2. 5.25.2 Session and Token Theft
  3. 5.35.3 MFA Fatigue and Push Abuse
  4. 5.45.4 Password Spray and Credential Stuffing
  5. 5.55.5 Service Account Compromise
  6. 5.65.6 Attacker Changes: MFA Methods, Roles and Credentials
  7. 5.75.7 Hybrid Pivots: On-Premises to Cloud
  8. 5.85.8 Account Compromise: Severity and Next Moves
  9. 5.9Module Summary and Knowledge Check
Module 6Phishing and Business Email Compromise Triage

Triaging reported phishing and business email compromise from the message, its delivery evidence and what recipients did with it: clicks and relayed sessions, attachments that run, consent grants, inbox rules and forwarding, the campaign scope and purge, each ending in a call, a severity and a next move.

Show 9 lessonsHide lessons
  1. 6.16.1 Reported Phishing: The First Read
  2. 6.26.2 Email Headers and Delivery Evidence
  3. 6.36.3 Clicks and Credential Submission
  4. 6.46.4 Malicious Attachments: Delivery to Execution
  5. 6.56.5 Consent Phishing and Malicious App Grants
  6. 6.66.6 Business Email Compromise: Inbox Rules and Forwarding
  7. 6.76.7 Campaign Scope: Recipients, Clicks and Purge
  8. 6.86.8 Phishing and BEC: Severity and Next Moves
  9. 6.9Module Summary and Knowledge Check
Module 7Malware and Ransomware Triage

Triaging malware and ransomware from the endpoint evidence: process trees and command lines, borrowed Windows binaries, credential dumping, persistence, lateral movement, Linux hosts, and the precursors that come before encryption, each ending in a call, a severity and a next move.

Show 9 lessonsHide lessons
  1. 7.17.1 Endpoint Alerts: Process Trees and Command Lines
  2. 7.27.2 Malicious Documents, Scripts and LOLBins
  3. 7.37.3 Credential Dumping on the Endpoint
  4. 7.47.4 Persistence Mechanisms
  5. 7.57.5 Lateral Movement From a Compromised Host
  6. 7.67.6 Linux Host Compromise: SSH, Cron and Web Shells
  7. 7.77.7 Ransomware Precursors: Staging, Backups and Shadow Copies
  8. 7.87.8 Malware and Ransomware: Severity and Next Moves
  9. 7.9Module Summary and Knowledge Check

Phase 3: Response

Module 9Incident Containment

Stopping attackers while the investigation continues: account, host, application and mailbox levers, each pulled in the system that holds it, in an order and at a time that leave no way back and give no warning, with the business cost measured and planned.

Show 9 lessonsHide lessons
  1. 9.19.1 Containment Options: Accounts, Hosts, Apps and Network
  2. 9.29.2 Session and Token Revocation
  3. 9.39.3 Password and MFA Reset Sequencing
  4. 9.49.4 Host Isolation and Evidence Preservation
  5. 9.59.5 App and Consent Removal
  6. 9.69.6 Containment Order Under Time Pressure
  7. 9.79.7 Containment Timing and Attacker Awareness
  8. 9.89.8 Containment Side Effects and Business Impact
  9. 9.9Module Summary and Knowledge Check
Module 10Escalation, Reporting and Handoff

Moving a triaged incident to the people who act on it: escalation by threshold and clock, communication on channels the attacker cannot read, the notification trigger, the fifteen-minute Triage Report at the right confidence, and handoffs to the response team and the next shift.

Show 9 lessonsHide lessons
  1. 10.110.1 Escalation Paths and Thresholds
  2. 10.210.2 Escalation Timing by Priority
  3. 10.310.3 Stakeholder Communication During Triage
  4. 10.410.4 Regulatory Notification Triggers
  5. 10.510.5 The Fifteen-Minute Triage Report
  6. 10.610.6 Triage Report: Findings, Confidence and Gaps
  7. 10.710.7 Handoff to Incident Response
  8. 10.810.8 Shift Handover for Open Incidents
  9. 10.9Module Summary and Knowledge Check
Module 11Automation and AI in Triage

Consuming what automation and AI hand the analyst: outputs read as inputs, enrichment whose silence is not clean, verdicts read for what they are about and overridden with a reason, automated containment reviewed for result, reach and aim, AI summaries checked claim by claim, and the narrow first actions that must be automatic because the attack is faster than the clock.

Show 7 lessonsHide lessons
  1. 11.111.1 Automation in the Triage Workflow
  2. 11.211.2 Automated Enrichment and Its Verification
  3. 11.311.3 Automated Verdicts and Analyst Override
  4. 11.411.4 Automated Containment: Review and Reversal
  5. 11.511.5 AI-Assisted Triage: Summaries and Verification
  6. 11.611.6 Fast-Moving Attacks and the Triage Clock
  7. 11.7Module Summary and Knowledge Check

Phase 4: Capstone

Module 12Capstone: A Full Incident Triage

One incident triaged end to end, one decision per section: an intrusion from a public web server to a tenant-wide mail grant in eight minutes, left unopened for a day, then validated, preserved, scoped, scored, contained, escalated and reported in one afternoon.

Show 8 lessonsHide lessons
  1. 12.112.1 Capstone Case: The Alert
  2. 12.212.2 Capstone Case: Alert Validation
  3. 12.312.3 Capstone Case: Evidence Preservation
  4. 12.412.4 Capstone Case: Scope and Blast Radius
  5. 12.512.5 Capstone Case: Severity and Priority
  6. 12.612.6 Capstone Case: Containment Plan
  7. 12.712.7 Capstone Case: Escalation and Notification
  8. 12.812.8 Capstone Case: The Triage Report

Phase 0: Course Resources

ResourcesCheatsheets

The instruments to know from memory, the artifact-type vocabulary that makes a question transfer between stacks, and ten cheatsheets, one per call and incident type, with a lookup page.

Show 11 lessonsHide lessons
  1. 1Alert Validation
  2. 2Evidence Preservation
  3. 3Scope and Grouping
  4. 4Severity and Priority
  5. 5Account Compromise
  6. 6Phishing and Business Email Compromise
  7. 7Malware and Ransomware
  8. 8Exfiltration and Intrusion
  9. 9Containment
  10. 10Escalation and Reporting
  11. 11Codes, Types and What They Prove
ResourcesCookbooks

The six calls of the first hour as runbooks, then the whole hour applied to account compromise, phishing and BEC, malware and ransomware, and exfiltration and intrusion. Every step names what it must produce, where it branches, and the query that starts it.

Show 11 lessonsHide lessons
  1. 1The Sixty-Minute Timeline
  2. 2Validating an Alert
  3. 3Preserving Evidence
  4. 4Scoping an Incident
  5. 5Setting Severity
  6. 6Containing
  7. 7Escalating and Handing Off
  8. 8Account Compromise
  9. 9Phishing and Business Email Compromise
  10. 10Malware and Ransomware
  11. 11Exfiltration and Intrusion
ResourcesLab Setup

Build a triage lab from a Microsoft 365 E5 trial, an Azure free account and a Sentinel trial workspace, or from Splunk Free and Elastic, with every cost and clock stated and a check for how far back the evidence reaches.

Show 4 lessonsHide lessons
  1. 1Building the Environment
  2. 2Generating Evidence to Triage
  3. 3Splunk and Elastic
  4. 4Verify, and End the Trials
ResourcesWalkthroughs

Seven real alerts from the course's records triaged start to finish with the clock running, including the wrong turns. Each turns on one judgment: when to stop, when not to, what a reset leaves, where access lives, what silence means, what a score is for, and when to stop asking an empty source.

Show 7 lessonsHide lessons
  1. 1The Cheap Check That Ends It
  2. 2When the Cheap Check Does Not Clear It
  3. 3The Reset That Contained Nothing
  4. 4A Grant Nobody Noticed
  5. 5The Alert With No Evidence Behind It
  6. 6The Score Was Right and the Call Was Wrong
  7. 7The Sixty Minutes That Went Nowhere
ResourcesPlaybooks

Nine playbooks, one per alert type the course triages: opened when the alert fires, each with pre-flight, a clearing check, what escalates it, an execution sequence, containment, a tiered disposition and what the handoff must say.

Show 9 lessonsHide lessons
  1. 1Impossible Travel and Unfamiliar Sign-In
  2. 2Session Token Theft
  3. 3Suspicious Application Consent
  4. 4Suspicious Process Execution
  5. 5Anomalous Data Egress
  6. 6Several Alerts, One Incident
  7. 7Inbox Rule or Forwarding
  8. 8Ransomware Precursor
  9. 9VPN or Edge Login
ResourcesPlayground

Practicing triage on the course's own records: what they hold, a practice loop that runs the hour on a real alert, where the records are thin, and the wider platform resources: guided investigations, the query console, the detection library and a DFIR toolkit.

ResourcesReferences & Further Reading

The primary sources this course relies on: Microsoft Learn pages for the portals, logs and containment actions it uses, NIST SP 800-61r3, the MITRE ATT&CK techniques its incidents map to, and the ICO's breach-notification guidance.

Project

ResourcesProject: Build Your Own Triage Kit

The FOR301 project: a brief for three artifacts you build for your own estate from what the course taught, a five-query first-look pack, a scorecard calibrated to your priority tiers, and a Triage Report template your escalation path accepts. No submission, no grading.

Show 1 lessonHide lessons
  1. 1The Brief

Course Completion

CompletionCourse Exam

Incident Triage and First Response end-of-course exam: a three-phase simulation testing whether you can apply the method to a situation the course did not walk through.

Show 1 lessonHide lessons
  1. 1Course Completion. Incident Triage and First Response

Course overview

The first hour of an incident decides most of how it ends: whether the evidence survives, whether the attacker keeps their way back in, and whether the people who need to act are told something they can act on. This course teaches the calls that hour is made of, from the alert to the handoff, and the records each one rests on.

✓ An alert is a detector's claim. You confirm it or dismiss it from the sign-ins, process events and mail trace behind it
✓ A password reset removes neither the application grant nor the inbox rule an attacker left, and containment has an order that does
✓ Severity is scored from evidence onto a scale you can defend, not copied from the tool that raised the alert
✓ A Triage Report says what is established, what is inferred and what is not yet known, so the next team starts from it rather than from zero

By the end you can take an alert you have never seen before to a call you can defend, inside the hour it matters.

How this course works

Every incident type in the course is triaged with the same six calls, practiced against the Northgate Engineering records in Defender KQL, Splunk SPL and PowerShell.

1. Validate the alert. True positive, false positive or benign, decided from the records behind it in five queries.

2. Preserve what expires first. Every source has a clock, and some of your own actions stop it. The capture order comes before the investigation.

3. Scope by what is shared. The alert names one entity. Scope is every account, device and application linked to it by a record, not by resemblance.

4. Score it. Severity and priority on a scorecard, with the overrides that must move a score and the limits of what a score can say.

5. Contain in order. The order that removes the access, what each lever destroys, and when acting alerts the attacker.

6. Escalate and hand off. The escalation path, the regulatory clock, and a Triage Report and package incident response can start from.

Four modules apply the calls to account compromise, phishing and business email compromise, malware and ransomware, and exfiltration and intrusion. A capstone works one incident end to end.

What this course assumes

No minimum experience and no prerequisite course. Every source is introduced from what it records, and every query is explained at first use.

What makes it go faster: exposure to any alert queue, in any tool. Not required. Every triage in the course is worked against records the course provides.

What this course does not cover: deep forensics in any single environment, detection engineering, and the investigation that follows triage. Triage hands off to those, and the handoff is taught.

Who this course is for

Anyone who is first to an alert and has to decide what happens next. There is no minimum experience and no gatekeeping.

✓ SOC analysts who work a queue and need calls they can defend at handover
✓ Security engineers and administrators who are on call for incidents in the systems they run
✓ Incident responders who want the first hour done the way they would do it themselves
✓ Team leads who need a shared way to validate, score and report, so two analysts reach the same call

What you'll learn

By the end of this course you will be able to:

✓ Confirm or dismiss an alert from the records behind it, in five queries that run on any SIEM
✓ Capture the evidence that expires first, in an order that holds against the clock
✓ Scope an incident by the entities it shares, and group alerts into incidents on links rather than resemblance
✓ Score severity and priority on a scorecard you can defend, and apply the overrides that must change it
✓ Triage account compromise, phishing and BEC, malware and ransomware, and exfiltration and intrusion, each to a call with its severity
✓ Contain in an order that removes the access, weighing what containment destroys and what it alerts the attacker to
✓ Escalate, test the notification clock, and hand off a Triage Report and package the next team can start from

Key course takeaways

✓ A five-query first look, in KQL, SPL and PowerShell, that answers who, where, what, what was sent and what else names it
✓ A scorecard that turns evidence into P1 to P4, with the overrides written down
✓ A containment order for identities, applications, mailboxes and devices, with each lever's side effects
✓ A ten-line Triage Report and a handoff package with an evidence register
✓ A five-script triage kit, read-only or dry run until you say otherwise
✓ A project brief that calibrates the queries, scorecard and report to your own estate

Lab Pack and Triage Kit

Most of the course's queries run in the browser against the lab corpus. The lab pack is what you take to your own estate: the five-script triage kit, with its test procedure, and the templates for the five-query pack, the scorecard and the Triage Report.

The kit: an identity snapshot, a phishing campaign scope with a purge preview, a Live Response endpoint collection, a Linux collection, and a containment script that runs as a dry run until you pass -Execute.

Incident Triage Lab Pack
5 kit scripts · test procedure · query pack, scorecard and Triage Report templates
Download Lab Pack (.zip)

Things you need to know

What are the prerequisites for this course?

There are no prerequisites. The course teaches incident triage from first principles. Familiarity with an alert queue, Microsoft Defender or Splunk will help you move faster, but none is required.

What are the device requirements?

A device with a modern browser. Most queries run in the browser against the lab corpus. To run the kit against real systems, Module 0 walks through building a lab from a Microsoft 365 trial and a free Splunk or Elastic instance, with every cost stated.

How will the course benefit your career?

The first hour is where an incident's outcome is mostly set, and the analyst who can make its calls and explain them is the one teams rely on. This course gives you the calls, the records behind them and the report that carries them on.

Usage rights and disclaimer

Course materials: Licensed for individual professional development. You may deploy the kit scripts, query packs and templates in your production environment. You may not redistribute course content or share account credentials.

Triage tools and scripts: All PowerShell, Bash, KQL and SPL artifacts are provided as-is. Test every script against a test tenant or device before using it in an incident. Containment actions have business impact.

Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
2scenarios
Take End of Course Exam

One random scenario per attempt. Certificate issued on pass.