Distinguish observed evidence from interpretation during first-pass SOC triage.
The reframe: A SOC analyst is not paid to guess faster. They are paid to reduce uncertainty faster. Evidence Evidence is directly observed: a process name, command line, host, user, timestamp, destination, hash, rule name, or log source. Evidence should be copyable by another analyst. Inference Inference connects evidence to meaning: possible credential theft, possible script execution, likely false positive from software deployment. Inference is allowed, but it should be labeled as inference. Next question The next question drives collection: what parent process created this, what other hosts saw the same hash, did the user authenticate from a new ASN,…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in