Investigating a SIEM alert: Windows events, timelines and scoping
What to do after an alert fires: confirm it in the underlying events, read the Windows security events and logon types that matter most, build a timeline, pivot on account, host and address to find the full scope, describe what happened in shared ATT&CK language, and close or escalate with a record someone else can follow.
- Level
- Intermediate
- Length
- About 50 minutes
- Contents
- 3 lessons · 1 video · final exam
- Status
- Published · updated 3 Oct 2026
Skills you'll practise
- Identify common Windows security event IDs and logon types and what each shows
- Build a timeline from raw events and pick out the first successful access and signs of persistence
- Scope an incident by pivoting on account, host and source address
- Distinguish password spraying from brute force in failed-logon patterns
- Classify an alert's outcome and write an investigation record that supports escalation
Course outline
- 1.From alert to investigation recordVideo · 3 min
- 2.The Windows events you will pivot onLesson · 16 min
- 3.Timeline and scopeLesson · 17 min
- 4.Deciding, recording and escalatingLesson · 15 min
- 5.Investigating a SIEM alert: Windows events, timelines and scoping: knowledge checkKnowledge check · 18 questions
- 6.A new local admin at 02:12Scenario
- 7.Final exam10 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- Microsoft Learn: Appendix L, Events to monitor (Windows security event IDs)
- Microsoft Learn: 4624(S) An account was successfully logged on (logon types)
- MITRE ATT&CK: T1110.003 Brute Force: Password Spraying
- MITRE ATT&CK: T1053.005 Scheduled Task/Job: Scheduled Task
- MITRE ATT&CK: Enterprise tactics
- NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations for Cybersecurity Risk Management (2025)
- NIST SP 800-92: Guide to Computer Security Log Management (2006)
- ASD's ACSC, CISA and partners: Best Practices for Event Logging and Threat Detection (2024)
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.