SOC analyst: triaging an alert end to end
For new SOC analysts, security-minded service desk staff and systems administrators who pick up alerts from a SIEM or XDR console. You should know what a SIEM does (Security monitoring basics is a good start) and be able to read sign-in and endpoint logs. Follows one alert from arrival to hand-off: validating it against the underlying events, enriching it with asset, identity and threat-intelligence context, scoping it, mapping it to MITRE ATT&CK, prioritising and escalating on risk rather than arrival order, and writing a record the next person can act on. Uses NIST SP 800-61 Revision 3 for the process and Microsoft Sentinel as the example console; the method applies to other SIEMs. Your organisation's incident response plan decides severity levels, who you escalate to and what containment you may perform; triage records hold personal data, so keep them in the approved system only. Investigating Windows events in depth is covered in a separate SIEM investigation course. Ends with a supervisor-graded triage exercise.
- Level
- Intermediate
- Length
- About 105 minutes
- Contents
- 5 lessons · final exam
- Status
- Published · updated 10 Oct 2026
Skills you'll practise
- Validate an alert against the underlying events and classify it as a true positive, benign positive, false positive or undetermined
- Enrich an alert with asset, identity and threat-intelligence context and estimate its scope across other accounts and hosts
- Map observed activity to MITRE ATT&CK tactics and techniques
- Prioritise and escalate an incident using risk evaluation factors rather than arrival order
- Write a triage record that supports hand-off, protects evidence and feeds back into detection tuning
Course outline
- 1.Validate an alert against the underlying events and classify itLesson · 22 min
- 2.Enrich an alert and estimate its scopeLesson · 20 min
- 3.Map observed activity to MITRE ATT&CK tactics and techniquesLesson · 16 min
- 4.Prioritise and escalate an incident using risk evaluation factorsLesson · 16 min
- 5.Write a triage record that supports hand-off and tuningLesson · 14 min
- 6.SOC analyst: triaging an alert end to end: knowledge checkKnowledge check · 14 questions
- 7.SOC analyst: triaging an alert end to end: practical exerciseKnowledge check · 1 question
- 8.Final exam10 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations for Cybersecurity Risk Management (publication page)
- NIST SP 800-61 Rev. 3 (PDF, April 2025): definitions, life cycle model and CSF 2.0 Community Profile (DE.AE, RS.MA, RS.AN)
- MITRE ATT&CK: Enterprise tactics
- MITRE ATT&CK: T1110.003 Brute Force: Password Spraying
- MITRE ATT&CK: T1078 Valid Accounts
- MITRE ATT&CK: T1114.003 Email Collection: Email Forwarding Rule
- MITRE ATT&CK: T1566.001 Phishing: Spearphishing Attachment
- MITRE ATT&CK: T1059.001 Command and Scripting Interpreter: PowerShell
- Microsoft Learn: Navigate, triage and manage Microsoft Sentinel incidents in the Azure portal
- Microsoft Learn: Investigate Microsoft Sentinel incidents in depth in the Azure portal
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.