Work through the first 30-minute triage note
Build a concise first-30-minute incident triage note that captures facts, scope, containment, and unknowns.
You have an endpoint alert, a user-reported MFA prompt, and a suspicious ERP login. The team needs a first triage note before additional responders join. Observed facts -> likely scope -> containment taken -> unknowns -> next step The common trap is writing a timeline dump full of raw alerts without extracting what is confirmed, what is suspected, and what action has already changed the situation. Step 1 Observed facts User reported unexpected MFA prompt at 08:41 PowerShell activity observed on finance laptop ERP login from unusual ASN at 08:46 Start with what is directly observed. This anchors the note…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in