Course

Security Alert Triage: Evidence, Scope, and Handoff

About this learning content: Courses, lessons, assessments, explanations and illustrations may be created with the help of artificial intelligence. We review and check the material and do our best to avoid incorrect or outdated information, but mistakes, omissions or ambiguous questions may remain. Please verify information before relying on it for professional, security, legal or operational decisions. Read the full notice or report an issue.
Difficulty Intermediate
Modules 3
Lessons 6
Time 4 hr 45 min
Language en
Created by Threat Intelligence Lab
Updated 11 September 2026
Security Alert TriageA normalized claim moves through telemetry verification, scope, hypothesis testing, severity, action, and learning.PRACTICAL SECURITY OPERATIONSSecurity Alert TriageClaimEvidenceScopeHandoffEVIDENCE → REASONING → DEFENSIBLE ACTION

About this course

Security alerts arrive as product-specific summaries, but analysts must decide what actually happened, who or what is affected, and whether response authority should be engaged. This course teaches new and developing SOC analysts a vendor-neutral triage workflow: normalize an alert into an evidence claim, verify telemetry health, scope entities and time, test competing explanations, separate confidence from impact and urgency, select a disposition, and create a concise handoff. It aligns daily triage with current NIST incident-response guidance while preserving the boundary between an alert, a cybersecurity event, and a confirmed incident. Completion means the learner can work an unfamiliar alert methodically, avoid uncontrolled pivoting, recommend authorized action, and feed verified outcomes back into detections and data quality.

What you'll learn

  • ✓ Translate an unfamiliar alert into a precise claim, required evidence, and initial safety checks.
  • ✓ Verify telemetry provenance and health before using absence or presence as investigative proof.
  • ✓ Scope affected entities and time with explicit pivots, stop rules, and competing hypotheses.
  • ✓ Set confidence, impact, urgency, disposition, and handoff actions independently and reproducibly.

Before you begin

You will get more from this course if these foundations are already familiar.

  • Basic security telemetry familiarity — Learners should recognize common security data such as authentication, endpoint, network, email, and cloud events. Experience with a particular SIEM or EDR product is not required.

Course content

Keep building