Skip to content

SOC analyst: triaging an alert end to end

For new SOC analysts, security-minded service desk staff and systems administrators who pick up alerts from a SIEM or XDR console. You should know what a SIEM does (Security monitoring basics is a good start) and be able to read sign-in and endpoint logs. Follows one alert from arrival to hand-off: validating it against the underlying events, enriching it with asset, identity and threat-intelligence context, scoping it, mapping it to MITRE ATT&CK, prioritising and escalating on risk rather than arrival order, and writing a record the next person can act on. Uses NIST SP 800-61 Revision 3 for the process and Microsoft Sentinel as the example console; the method applies to other SIEMs. Your organisation's incident response plan decides severity levels, who you escalate to and what containment you may perform; triage records hold personal data, so keep them in the approved system only. Investigating Windows events in depth is covered in a separate SIEM investigation course. Ends with a supervisor-graded triage exercise.

Level
Intermediate
Length
About 105 minutes
Contents
5 lessons · final exam
Status
Published · updated 10 Oct 2026

Skills you'll practise

  • Validate an alert against the underlying events and classify it as a true positive, benign positive, false positive or undetermined
  • Enrich an alert with asset, identity and threat-intelligence context and estimate its scope across other accounts and hosts
  • Map observed activity to MITRE ATT&CK tactics and techniques
  • Prioritise and escalate an incident using risk evaluation factors rather than arrival order
  • Write a triage record that supports hand-off, protects evidence and feeds back into detection tuning

Course outline

  1. 1.Validate an alert against the underlying events and classify itLesson · 22 min
  2. 2.Enrich an alert and estimate its scopeLesson · 20 min
  3. 3.Map observed activity to MITRE ATT&CK tactics and techniquesLesson · 16 min
  4. 4.Prioritise and escalate an incident using risk evaluation factorsLesson · 16 min
  5. 5.Write a triage record that supports hand-off and tuningLesson · 14 min
  6. 6.SOC analyst: triaging an alert end to end: knowledge checkKnowledge check · 14 questions
  7. 7.SOC analyst: triaging an alert end to end: practical exerciseKnowledge check · 1 question
  8. 8.Final exam10 questions · passing it completes the course, so people who already know the material can test out

Sources it draws on

The lessons and questions are written from these references, so learners can go back to the original.

See it with your own jobs and topics

Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.