Build a timeline from raw events
Create a concise incident timeline by ordering events, normalizing entities, and separating facts from interpretations.
You need to explain whether Mia's laptop compromise started before or after a successful identity session, using IdP sign-ins, Windows 4688 process events, DNS logs, and EDR alerts. Normalize time, normalize entities, select story-changing events, separate fact from inference The common trap is pasting raw SIEM rows in the ticket. That looks thorough but forces every reviewer to rebuild the sequence under pressure. Normalize time Convert IdP UTC, endpoint local time, and proxy timestamps into UTC. Preserve original timezone only in the evidence notes. This prevents false sequence errors, especially when identity and endpoint tools disagree by offset or ingestion…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in