Incident Triage and First Response
Read the record. Make the call. Hand it on.
Make the first hour's calls from the records, not the alert. Confirm what fired, capture what expires, scope and score the incident, contain it in an order that removes the access, and hand it off with a report the next team can act on.
What you'll be able to do
“Coming from an admin background, the incident triage course forced me to think a little when things are hitting the fan. Appreciate the platform and what you guys are trying to do. So far, it's worth my subscription.”
Course Syllabus
Every module and every lesson. The first three modules are open; the rest open on a click.
Download the full syllabus (PDF)
Phase 1: Foundations
Incident Triage and First Response: the first hour of an incident as five decisions, taught against a month of records from an attacked company. What the course covers, how it is built, where to practice, and a six-scenario check of whether it fits you.
Show 6 lessonsHide lessons
- 0.10.1 Incident Triage and the First HourPreview
- 0.20.2 Triage and Incident Response: The Handoff PointPreview
- 0.30.3 The Triage ClockPreview
- 0.40.4 Your Lab Environment and EquivalentsPreview
- 0.50.5 Building the Triage Lab: Steps and CostsPreview
- 0.60.6 Triage Tools: Scorecard, Query Pack and Triage ReportPreview
What an alert claims, how to test the claim against the evidence underneath it, and how to classify the result as a true positive, a false positive, benign activity, or unresolved, across identity, endpoint, email, cloud and network alerts.
Show 9 lessonsHide lessons
- 1.11.1 Anatomy of a Security Alert
- 1.21.2 True Positives, False Positives and Benign Activity
- 1.31.3 Detection Rules Behind an Alert
- 1.41.4 The Five-Query Triage Pack
- 1.51.5 First Look: Sign-In and Identity Alerts
- 1.61.6 First Look: Endpoint Alerts
- 1.71.7 First Look: Email and Cloud Alerts
- 1.81.8 First Look: Network Alerts
- 1.9Module Summary and Knowledge Check
What evidence an incident leaves, how long each kind lasts, and the capture order that keeps what the investigation will need before time, the attacker or your own containment destroys it.
Show 9 lessonsHide lessons
- 2.12.1 Evidence Volatility by Source
- 2.22.2 Order of Evidence Capture
- 2.32.3 Identity Evidence: Sessions, Tokens and Log Retention
- 2.42.4 Endpoint Evidence: Memory, Processes and Connections
- 2.52.5 Cloud Evidence: Retention Limits and Audit Gaps
- 2.62.6 First-Hour Evidence Capture
- 2.72.7 Preservation and Containment Trade-Offs
- 2.82.8 Evidence Gaps and Their Documentation
- 2.9Module Summary and Knowledge Check
What an incident includes and what it can reach: scope built from links rather than the alert queue, pivots taken to completion, the blast radius of accounts, machines and data, alerts grouped on shared entities, a sourced triage timeline, and every claim graded by the evidence that carries it.
Show 9 lessonsHide lessons
- 3.13.1 Incident Scope: Users, Hosts and Time
- 3.23.2 Pivoting on Users, Hosts and IP Addresses
- 3.33.3 Blast Radius: Accounts and Access
- 3.43.4 Blast Radius: Endpoints and Lateral Reach
- 3.53.5 Blast Radius: Applications and Data
- 3.63.6 Related Alerts and Incident Grouping
- 3.73.7 The Triage Timeline
- 3.83.8 Scope Confidence and Its Limits
- 3.9Module Summary and Knowledge Check
How bad an incident is and how fast it must be acted on, scored from evidence on an eight-question card, turned into a priority tier and a response clock, with overrides for the features a total cannot capture and a record for the cases where the card runs out.
Show 9 lessonsHide lessons
- 4.14.1 Severity and Urgency
- 4.24.2 The Triage Scorecard: Eight Questions
- 4.34.3 The Triage Scorecard: Scoring From Evidence
- 4.44.4 The Triage Scorecard: Unanswered Questions
- 4.54.5 Priority Tiers and Response Timelines
- 4.64.6 Severity Overrides
- 4.74.7 Prioritization With Conflicting Evidence
- 4.84.8 Scorecard Limits and Analyst Judgment
- 4.9Module Summary and Knowledge Check
Phase 2: Incident Triage
Triaging a compromised account from its evidence: suspicious sign-ins, stolen sessions, MFA fatigue, password spray and brute force, service accounts, the changes attackers make to keep access, and hybrid pivots, each ending in a call, a severity and a next move.
Show 9 lessonsHide lessons
- 5.15.1 Suspicious Sign-Ins: Location, Device and Risk
- 5.25.2 Session and Token Theft
- 5.35.3 MFA Fatigue and Push Abuse
- 5.45.4 Password Spray and Credential Stuffing
- 5.55.5 Service Account Compromise
- 5.65.6 Attacker Changes: MFA Methods, Roles and Credentials
- 5.75.7 Hybrid Pivots: On-Premises to Cloud
- 5.85.8 Account Compromise: Severity and Next Moves
- 5.9Module Summary and Knowledge Check
Triaging reported phishing and business email compromise from the message, its delivery evidence and what recipients did with it: clicks and relayed sessions, attachments that run, consent grants, inbox rules and forwarding, the campaign scope and purge, each ending in a call, a severity and a next move.
Show 9 lessonsHide lessons
- 6.16.1 Reported Phishing: The First Read
- 6.26.2 Email Headers and Delivery Evidence
- 6.36.3 Clicks and Credential Submission
- 6.46.4 Malicious Attachments: Delivery to Execution
- 6.56.5 Consent Phishing and Malicious App Grants
- 6.66.6 Business Email Compromise: Inbox Rules and Forwarding
- 6.76.7 Campaign Scope: Recipients, Clicks and Purge
- 6.86.8 Phishing and BEC: Severity and Next Moves
- 6.9Module Summary and Knowledge Check
Triaging malware and ransomware from the endpoint evidence: process trees and command lines, borrowed Windows binaries, credential dumping, persistence, lateral movement, Linux hosts, and the precursors that come before encryption, each ending in a call, a severity and a next move.
Show 9 lessonsHide lessons
- 7.17.1 Endpoint Alerts: Process Trees and Command Lines
- 7.27.2 Malicious Documents, Scripts and LOLBins
- 7.37.3 Credential Dumping on the Endpoint
- 7.47.4 Persistence Mechanisms
- 7.57.5 Lateral Movement From a Compromised Host
- 7.67.6 Linux Host Compromise: SSH, Cron and Web Shells
- 7.77.7 Ransomware Precursors: Staging, Backups and Shadow Copies
- 7.87.8 Malware and Ransomware: Severity and Next Moves
- 7.9Module Summary and Knowledge Check
Triaging intrusions that cross the network edge, hosts, the identity layer and cloud applications: data leaving, cloud downloads, persistence in applications, perimeter alerts, VPN compromise and command-and-control, scoped across domains and scored as one incident.
Show 9 lessonsHide lessons
- 8.18.1 Data Exfiltration: Volume, Destination and Timing
- 8.28.2 Cloud Storage and SaaS Data Access
- 8.38.3 Cloud Persistence: App Credentials and Federation
- 8.48.4 Perimeter Alerts: Firewall and Proxy Evidence
- 8.58.5 Edge Device and VPN Compromise
- 8.68.6 Command-and-Control Beaconing
- 8.78.7 Exfiltration and Intrusion: Scope Across Domains
- 8.88.8 Exfiltration and Intrusion: Severity and Next Moves
- 8.9Module Summary and Knowledge Check
Phase 3: Response
Stopping attackers while the investigation continues: account, host, application and mailbox levers, each pulled in the system that holds it, in an order and at a time that leave no way back and give no warning, with the business cost measured and planned.
Show 9 lessonsHide lessons
- 9.19.1 Containment Options: Accounts, Hosts, Apps and Network
- 9.29.2 Session and Token Revocation
- 9.39.3 Password and MFA Reset Sequencing
- 9.49.4 Host Isolation and Evidence Preservation
- 9.59.5 App and Consent Removal
- 9.69.6 Containment Order Under Time Pressure
- 9.79.7 Containment Timing and Attacker Awareness
- 9.89.8 Containment Side Effects and Business Impact
- 9.9Module Summary and Knowledge Check
Moving a triaged incident to the people who act on it: escalation by threshold and clock, communication on channels the attacker cannot read, the notification trigger, the fifteen-minute Triage Report at the right confidence, and handoffs to the response team and the next shift.
Show 9 lessonsHide lessons
- 10.110.1 Escalation Paths and Thresholds
- 10.210.2 Escalation Timing by Priority
- 10.310.3 Stakeholder Communication During Triage
- 10.410.4 Regulatory Notification Triggers
- 10.510.5 The Fifteen-Minute Triage Report
- 10.610.6 Triage Report: Findings, Confidence and Gaps
- 10.710.7 Handoff to Incident Response
- 10.810.8 Shift Handover for Open Incidents
- 10.9Module Summary and Knowledge Check
Consuming what automation and AI hand the analyst: outputs read as inputs, enrichment whose silence is not clean, verdicts read for what they are about and overridden with a reason, automated containment reviewed for result, reach and aim, AI summaries checked claim by claim, and the narrow first actions that must be automatic because the attack is faster than the clock.
Show 7 lessonsHide lessons
- 11.111.1 Automation in the Triage Workflow
- 11.211.2 Automated Enrichment and Its Verification
- 11.311.3 Automated Verdicts and Analyst Override
- 11.411.4 Automated Containment: Review and Reversal
- 11.511.5 AI-Assisted Triage: Summaries and Verification
- 11.611.6 Fast-Moving Attacks and the Triage Clock
- 11.7Module Summary and Knowledge Check
Phase 4: Capstone
One incident triaged end to end, one decision per section: an intrusion from a public web server to a tenant-wide mail grant in eight minutes, left unopened for a day, then validated, preserved, scoped, scored, contained, escalated and reported in one afternoon.
Show 8 lessonsHide lessons
- 12.112.1 Capstone Case: The Alert
- 12.212.2 Capstone Case: Alert Validation
- 12.312.3 Capstone Case: Evidence Preservation
- 12.412.4 Capstone Case: Scope and Blast Radius
- 12.512.5 Capstone Case: Severity and Priority
- 12.612.6 Capstone Case: Containment Plan
- 12.712.7 Capstone Case: Escalation and Notification
- 12.812.8 Capstone Case: The Triage Report
Phase 0: Course Resources
The instruments to know from memory, the artifact-type vocabulary that makes a question transfer between stacks, and ten cheatsheets, one per call and incident type, with a lookup page.
The six calls of the first hour as runbooks, then the whole hour applied to account compromise, phishing and BEC, malware and ransomware, and exfiltration and intrusion. Every step names what it must produce, where it branches, and the query that starts it.
Build a triage lab from a Microsoft 365 E5 trial, an Azure free account and a Sentinel trial workspace, or from Splunk Free and Elastic, with every cost and clock stated and a check for how far back the evidence reaches.
Show 4 lessonsHide lessons
Seven real alerts from the course's records triaged start to finish with the clock running, including the wrong turns. Each turns on one judgment: when to stop, when not to, what a reset leaves, where access lives, what silence means, what a score is for, and when to stop asking an empty source.
Nine playbooks, one per alert type the course triages: opened when the alert fires, each with pre-flight, a clearing check, what escalates it, an execution sequence, containment, a tiered disposition and what the handoff must say.
Practicing triage on the course's own records: what they hold, a practice loop that runs the hour on a real alert, where the records are thin, and the wider platform resources: guided investigations, the query console, the detection library and a DFIR toolkit.
The primary sources this course relies on: Microsoft Learn pages for the portals, logs and containment actions it uses, NIST SP 800-61r3, the MITRE ATT&CK techniques its incidents map to, and the ICO's breach-notification guidance.
Project
The FOR301 project: a brief for three artifacts you build for your own estate from what the course taught, a five-query first-look pack, a scorecard calibrated to your priority tiers, and a Triage Report template your escalation path accepts. No submission, no grading.
Show 1 lessonHide lessons
Course Completion
Incident Triage and First Response end-of-course exam: a three-phase simulation testing whether you can apply the method to a situation the course did not walk through.
Show 1 lessonHide lessons
Course overview
The first hour of an incident decides most of how it ends: whether the evidence survives, whether the attacker keeps their way back in, and whether the people who need to act are told something they can act on. This course teaches the calls that hour is made of, from the alert to the handoff, and the records each one rests on.
By the end you can take an alert you have never seen before to a call you can defend, inside the hour it matters.
How this course works
Every incident type in the course is triaged with the same six calls, practiced against the Northgate Engineering records in Defender KQL, Splunk SPL and PowerShell.
1. Validate the alert. True positive, false positive or benign, decided from the records behind it in five queries.
2. Preserve what expires first. Every source has a clock, and some of your own actions stop it. The capture order comes before the investigation.
3. Scope by what is shared. The alert names one entity. Scope is every account, device and application linked to it by a record, not by resemblance.
4. Score it. Severity and priority on a scorecard, with the overrides that must move a score and the limits of what a score can say.
5. Contain in order. The order that removes the access, what each lever destroys, and when acting alerts the attacker.
6. Escalate and hand off. The escalation path, the regulatory clock, and a Triage Report and package incident response can start from.
Four modules apply the calls to account compromise, phishing and business email compromise, malware and ransomware, and exfiltration and intrusion. A capstone works one incident end to end.
What this course assumes
No minimum experience and no prerequisite course. Every source is introduced from what it records, and every query is explained at first use.
What makes it go faster: exposure to any alert queue, in any tool. Not required. Every triage in the course is worked against records the course provides.
What this course does not cover: deep forensics in any single environment, detection engineering, and the investigation that follows triage. Triage hands off to those, and the handoff is taught.
Who this course is for
Anyone who is first to an alert and has to decide what happens next. There is no minimum experience and no gatekeeping.
What you'll learn
By the end of this course you will be able to:
Key course takeaways
Lab Pack and Triage Kit
Most of the course's queries run in the browser against the lab corpus. The lab pack is what you take to your own estate: the five-script triage kit, with its test procedure, and the templates for the five-query pack, the scorecard and the Triage Report.
The kit: an identity snapshot, a phishing campaign scope with a purge preview, a Live Response endpoint collection, a Linux collection, and a containment script that runs as a dry run until you pass -Execute.
Things you need to know
What are the prerequisites for this course?
There are no prerequisites. The course teaches incident triage from first principles. Familiarity with an alert queue, Microsoft Defender or Splunk will help you move faster, but none is required.
What are the device requirements?
A device with a modern browser. Most queries run in the browser against the lab corpus. To run the kit against real systems, Module 0 walks through building a lab from a Microsoft 365 trial and a free Splunk or Elastic instance, with every cost stated.
How will the course benefit your career?
The first hour is where an incident's outcome is mostly set, and the analyst who can make its calls and explain them is the one teams rely on. This course gives you the calls, the records behind them and the report that carries them on.
Usage rights and disclaimer
Course materials: Licensed for individual professional development. You may deploy the kit scripts, query packs and templates in your production environment. You may not redistribute course content or share account credentials.
Triage tools and scripts: All PowerShell, Bash, KQL and SPL artifacts are provided as-is. Test every script against a test tenant or device before using it in an incident. Containment actions have business impact.
Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.
End of Course Exam
Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.
One random scenario per attempt. Certificate issued on pass.