S — Sources and safety
Define mission, evidence sources, source health, owners, privacy, retention, and non-operational boundaries.
Complete an end-to-end fictional defensive investigation using log collection, normalization, correlation, alert design, severity, priority, triage questions, evidence review, escalation, case management, dashboards, metrics, tuning, rollback, closure, and reopening.
Lesson Progress
High School Advanced • A6: SIEM and Alert Triage Concepts • Lesson 10 of 10
Readiness Check
0/6 ready
Professional Hook
Fictional Northbridge has strong evidence that a temporary role and session continued after expiration. Yet extension evidence is delayed, group evidence is Degraded, service impact is not confirmed, and recovery is incomplete. The professional goal is not to force a dramatic final label. It is to make the strongest evidence-supported decision, assign the right owners, preserve the right uncertainty, and define exactly what must happen next.
Weak conclusion
“The SIEM proved malicious privileged access and the identity team fixed it.”
Strong conclusion
“The SIEM supported stale authority and active session evidence after expiration. Authorized revocation ended the immediate condition. Historical authorization, group reconciliation, residual risk, and closure remain under review.”
Exactly Five Learning Objectives
Objective 1
Conduct a complete fictional SIEM triage workflow from alert intake through evidence review, prioritization, escalation, case management, quality improvement, closure, and reopening.
Objective 2
Reconstruct fictional evidence using source health, event time, collection time, processing time, normalization, enrichment, correlation, provenance, limitations, and alternative explanations.
Objective 3
Assign fictional severity, confidence, priority, owners, deadlines, escalation levels, case states, validation requirements, closure criteria, and reopen triggers.
Objective 4
Evaluate fictional alert noise, duplicate delivery, grouping, thresholds, expected activity, source defects, false-positive risk, false-negative risk, rollback, and coverage preservation.
Objective 5
Create a portfolio-ready fictional SIEM Triage Capstone Package containing an alert contract, evidence matrix, chronology, triage record, escalation plan, case notes, dashboard review, tuning proposal, leadership brief, residual-risk record, and reflection.
Why This Matters
Fictional SIEM work fails when teams treat logs, alerts, severity, priority, triage, escalation, notes, dashboards, and tuning as separate activities. A parser defect can distort normalization. A normalization defect can distort correlation. A correlation defect can distort severity. A priority error can delay review. A weak note can hide uncertainty. A bad metric can reward premature closure. A broad tuning change can hide the next important condition.
Sources, parsing, normalization, enrichment, correlation, timing, health, and provenance must remain traceable.
Severity, confidence, priority, state, escalation, actions, closure, and reopening must remain evidence-supported.
Metrics, tuning, validation, rollback, ownership, debt, residual risk, and review must preserve mission coverage.
Capstone Framework
Define mission, evidence sources, source health, owners, privacy, retention, and non-operational boundaries.
Preserve source values, parsed fields, normalized values, enrichment, transformations, timing, and limitations.
Join identity, role, group, extension, session, service, destination, change, owner, and health relationships.
Document observation, primary question, evidence, non-proof statements, severity, confidence, priority, alternatives, and triggers.
Ask authorization, effective-access, service, impact, source-health, scope, alternative, ownership, and closure questions.
Name owners, levels, deadlines, handoff acceptance, authorized actions, validation, and de-escalation criteria.
Maintain chronology, notes, evidence ledger, decisions, state changes, residual uncertainty, closure, and reopening.
Use dashboards, metrics, root cause, tuning, break conditions, shadow comparison, rollback, debt, and lifecycle review.
Advanced Vocabulary
A fictional end-to-end defensive review combining alert interpretation, evidence analysis, source health, prioritization, escalation, case management, quality improvement, closure, and reopening.
A fictional statement of what an alert observes, which evidence it requires, how source health affects it, what it does not prove, and which defender question it supports.
A fictional set of related normalized records joined by identity, device, service, destination, session, approval, timing, owner, or source-health relationships.
A fictional record of where evidence originated, how it was parsed, normalized, enriched, transformed, and used.
A fictional judgment about how reliable and complete available evidence is for a specific conclusion.
A fictional estimate of potential consequence if the observed condition is meaningful.
A fictional decision about review urgency using severity, confidence, active effect, scope, source health, time sensitivity, ownership, and recoverability.
A fictional register of observation, authorization, effective-access, service, source-health, scope, impact, alternatives, ownership, and closure questions.
A fictional classification describing routine, specialist, multi-owner, time-sensitive mission, or leadership review.
A fictional lifecycle label such as New, In Review, Conditional, Expected, Source-Degraded, Unknown, Escalated, Resolved, or Reopened.
A fictional change that prevents grouping, expected handling, or suppression from hiding meaningful identity, session, destination, service, severity, source-health, timing, scope, owner, or result differences.
A fictional required validation check before a rule, tuning change, state transition, escalation exit, or closure decision is approved.
A fictional important question or evidence limitation that remains unresolved after the current review.
A fictional risk that remains after approved actions, validation, and decisions are complete.
A fictional documented requirement that must be satisfied before a case can be resolved.
A fictional new-evidence, failed-validation, changed-scope, repeated-behavior, source-recovery, or residual-risk condition requiring renewed review.
Capstone Context
Northbridge Student-Support Cooperative, a completely invented educational support organization.
Provide reliable scheduling, counseling coordination, resource referrals, and family-support workflows for fictional partner schools.
Student Assistance Coordination Service, used by fictional staff to manage time-sensitive support referrals.
Permanent staff roles, temporary recovery roles, supplier support assignments, and service-owner approvals.
Fictional identity, role, group, approval, extension, session, service, destination, change, source-health, and case records.
Every organization, identity, field, record, service, owner, date, alert, action, decision, and outcome is invented and non-operational.
Capstone Stage 1
Provides fictional identity category, sponsor, owner, and lifecycle state.
Required fields
identity_id, identity_category, lifecycle_state, sponsor_id, owner_role, event_time
Limitation
Does not prove current role assignment, effective access, or session activity.
Provides fictional role assignment, approval, extension, revocation, purpose, and scope.
Required fields
identity_id, role_category, role_state, approval_start, approval_end, purpose, scope, event_time
Limitation
Role assignment does not prove current group membership or exercised access.
Provides fictional effective group membership and synchronization state.
Required fields
identity_id, group_category, membership_state, sync_state, event_time
Limitation
Delayed synchronization makes exact effective access uncertain.
Provides fictional time-bounded emergency-role extensions.
Required fields
identity_id, role_category, extension_id, extension_start, extension_end, approver_role, scope, event_time
Limitation
Ingestion delay may hide a valid extension or delay proof that none exists.
Provides fictional session, identity, device, service, destination, operation category, result, start, and end.
Required fields
session_id, identity_id, device_category, service_id, destination_category, operation_category, result, event_time
Limitation
A session does not prove harmful intent or privileged modification.
Provides fictional availability, error, user-impact, dependency, and recovery states.
Required fields
service_id, availability_state, error_state, impact_category, recovery_state, event_time
Limitation
Normal availability does not prove access was authorized or necessary.
Provides fictional maintenance, migration, recovery, owner, start, end, scope, and validation.
Required fields
change_id, owner_role, purpose, scope, start_time, end_time, expected_behavior, validation_state
Limitation
A change explains only activity matching its exact scope and time.
Provides fictional freshness, completeness, schema, parser, queue, blind-period, conflict, replay, and recovery state.
Required fields
source_id, health_state, affected_period, freshness, completeness, schema_state, parser_state, recovery_state
Limitation
Health metadata describes evidence quality, not the underlying activity.
Capstone Stage 2
Event time
08:58
Collection time
08:59
Processing time
09:00
Fictional record
identity_id=NB-ID-042; role_category=temporary-recovery; role_state=Active; approval_end=09:00; purpose=service-recovery
Supports
The fictional role remained assigned near the approved end time.
Does not prove
Does not prove a valid extension, effective group access, session activity, misuse, or service impact.
Event time
09:02
Collection time
09:11
Processing time
09:12
Fictional record
identity_id=NB-ID-042; group_category=recovery-admin; membership_state=Active; sync_state=Delayed
Supports
Fictional effective group membership may still be active.
Does not prove
Delayed evidence does not establish the exact state at every minute.
Event time
08:54
Collection time
09:18
Processing time
09:19
Fictional record
identity_id=NB-ID-042; role_category=temporary-recovery; extension_state=None-Visible; source_delay=24-minutes
Supports
No extension is visible in the fictional SIEM at processing time.
Does not prove
The delay prevents a confident source-side absence conclusion.
Event time
09:04
Collection time
09:05
Processing time
09:06
Fictional record
session_id=NB-SES-881; identity_id=NB-ID-042; service_id=NB-SVC-07; destination_category=coordination-admin; operation_category=configuration-review; result=Success
Supports
One fictional session continued after approval_end and reached the critical service.
Does not prove
Does not prove unauthorized use, harmful intent, privileged modification, or user impact.
Event time
09:07
Collection time
09:08
Processing time
09:09
Fictional record
service_id=NB-SVC-07; availability_state=Normal; error_state=No-Increase; impact_category=None-Confirmed; recovery_state=Stable
Supports
No current fictional service disruption is confirmed.
Does not prove
Normal service health does not prove the activity was expected or authorized.
Event time
08:20
Collection time
08:21
Processing time
08:22
Fictional record
change_id=NB-CHG-114; purpose=service-recovery; scope=database-reconciliation; start=08:15; end=08:55; destination=coordination-database
Supports
A fictional approved recovery change existed before the alert.
Does not prove
The change ended before the observed session and covers a different destination.
Event time
09:00
Collection time
09:00
Processing time
09:01
Fictional record
source_id=SRC-03; health_state=Degraded; affected_period=08:50-09:25; freshness=Delayed; completeness=Conditional
Supports
Group-state evidence is not fully reliable for normal-confidence conclusions.
Does not prove
Source degradation does not prove effective access remained active or inactive.
Event time
09:00
Collection time
09:00
Processing time
09:01
Fictional record
source_id=SRC-04; health_state=Conditional; affected_period=08:45-09:30; freshness=Delayed; completeness=Unknown
Supports
Extension evidence may be incomplete at alert time.
Does not prove
The source state does not prove a valid extension exists.
Capstone Stage 3
Source value
role_state=Active; approval_end=09:00
Normalized value
authorization.assignment_state=active; authorization.window_state=expired
Transformation
Mapped source role state and compared approval_end with fictional event time.
Risk
The expired interpretation may change if a valid delayed extension exists.
Source value
membership_state=Active; sync_state=Delayed
Normalized value
access.group_state=active; evidence.group_confidence=conditional
Transformation
Preserved source state while lowering confidence because of source degradation.
Risk
Normalized Active must not become proof of exact effective access.
Source value
extension_state=None-Visible; source_delay=24-minutes
Normalized value
authorization.extension_state=unknown
Transformation
Converted no-visible evidence under delay into Unknown rather than None.
Risk
Mapping no-visible to no-extension would create false certainty.
Source value
operation_category=configuration-review; result=Success
Normalized value
activity.category=administrative-review; activity.result=success
Transformation
Mapped a source-specific operation into a shared category.
Risk
The canonical category may hide source-specific detail.
Source value
availability_state=Normal; impact_category=None-Confirmed
Normalized value
service.active_impact=false; service.impact_confidence=moderate
Transformation
Combined healthy service evidence with owner-independent availability fields.
Risk
No current impact does not prove no authority, privacy, or evidence risk.
Source value
change end=08:55; session=09:04; destination mismatch
Normalized value
change.match_state=partial
Transformation
Compared identity, time, service, destination, and purpose.
Risk
Partial match must not become full approval or full contradiction.
Capstone Stage 4
Logic
Join fictional role, group, extension, and session records using identity_id.
Result
One identity connects assignment, potential effective access, extension evidence, and active session.
Limitation
Identity equality does not prove the same actor controlled every record.
Logic
Compare fictional session event time with approval_end and visible extension window.
Result
Session occurs after approval_end and no valid matching extension is currently visible.
Limitation
Extension delay keeps authorization confidence below High.
Logic
Join fictional session destination and service catalog.
Result
Session reaches a critical student-support administrative destination.
Limitation
Criticality describes potential consequence, not current impact.
Logic
Compare fictional session identity, service, destination, purpose, and time with approved changes.
Result
Existing change explains recovery context but not the observed time and destination.
Limitation
The change remains a partial alternative.
Logic
Attach fictional group and extension source-health states.
Result
Observation confidence is stronger than authorization confidence.
Limitation
Missing or delayed evidence cannot become absence.
Logic
Attach fictional service availability and user-impact evidence.
Result
Potential severity is High, but active service impact is not confirmed.
Limitation
No current impact does not remove authority or privacy concerns.
Capstone Stage 5
| Field | Fictional value |
|---|---|
| Alert title | Temporary Recovery Role and Session Continue after Approved End |
| Primary defender question | Did a fictional temporary recovery identity retain effective authority or session activity beyond its current approved authorization window? |
| Neutral observation | A fictional temporary recovery role and one session remain Active after approval_end. Extension evidence is delayed, group evidence is Degraded, and current service impact is not confirmed. |
| Required evidence | Role, group, extension, session, service, change, owner, timing, and source-health evidence. |
| Severity | High because privileged authority may affect a critical student-support service. |
| Confidence | Moderate because role and session evidence are Healthy while extension and group evidence are limited. |
| Initial priority | High because the session is active, the authorization window ended, and delay may reduce the response opportunity. |
| What the alert supports | A time-sensitive fictional stale-authority review involving identity, source, and service owners. |
| What the alert does not prove | It does not prove harmful intent, unauthorized use, privileged modification, complete scope, or current service impact. |
| Source-health behavior | No-visible extension becomes Unknown when the source is delayed; missing group evidence cannot become false absence. |
| Expected alternatives | Valid delayed extension, synchronization delay, partial maintenance context, stale owner context, or incomplete recovery. |
| Review trigger | New session, new destination, active impact, missed owner deadline, source-health change, or scope expansion. |
Capstone Stage 6
Evidence
Temporary privileged authority reaches a critical service.
Assessment
High severity.
Limitation
Potential consequence is not current impact.
Evidence
Healthy role and session evidence show activity after approval_end.
Assessment
High observation confidence.
Limitation
Observation does not establish authorization.
Evidence
Extension source is Conditional and group source is Degraded.
Assessment
Moderate authorization confidence.
Limitation
No valid extension is visible, but source-side absence is not yet confirmed.
Evidence
Service source shows Normal availability and no current error increase.
Assessment
No confirmed active service impact.
Limitation
Authority and privacy concerns may still exist.
Evidence
Session remains Active after expiration and owner responses are pending.
Assessment
High urgency.
Limitation
Urgency does not prove harmful behavior.
Evidence
One identity, one session, one critical service, and one destination are observed.
Assessment
Bounded current scope with possible wider scope unknown.
Limitation
Degraded group evidence limits complete scope.
Evidence
Role revocation and session closure exist through authorized owner processes.
Assessment
Potentially recoverable with validation.
Limitation
Technical action does not complete historical authorization.
Evidence
High severity, Moderate confidence, active session, short response window, and limited authorization evidence.
Assessment
High priority.
Limitation
Priority must change when evidence changes.
Capstone Stage 7
Question
Which fictional records support role and session activity after approval_end?
Evidence needed
Role event, approval_end, session event, event times, source health, and correlation explanation.
Owner
Case analyst and source owners
Deadline
Immediate
Question
Did a valid fictional extension exist for the identity, role, service, destination, purpose, and alert period?
Evidence needed
Source-side extension record, scope, approver, start, end, purpose, and source health.
Owner
Identity owner and extension-source owner
Deadline
30 minutes
Question
Did fictional group membership and active sessions preserve effective authority after expiration?
Evidence needed
Group state, synchronization state, session state, device relationship, operation category, and result.
Owner
Identity owner and group-source owner
Deadline
30 minutes
Question
Did the fictional activity affect service availability, users, privacy, evidence, or recovery?
Evidence needed
Service state, errors, user-impact category, owner statement, destination purpose, and recovery state.
Owner
Service owner
Deadline
45 minutes
Question
Does the fictional recovery change, synchronization delay, or delayed extension fully explain the observation?
Evidence needed
Change scope, time, destination, owner, expected behavior, source health, and extension event time.
Owner
Change, identity, and source owners
Deadline
45 minutes
Question
Are additional fictional identities, sessions, services, destinations, devices, or periods affected?
Evidence needed
Unique relationship review, duplicate handling, source coverage, service dependencies, and blind periods.
Owner
Case analyst and SIEM quality owner
Deadline
1 hour
Question
Which conclusions are limited by fictional Degraded or Conditional evidence?
Evidence needed
Freshness, completeness, schema, parser, queue, coverage, conflict, recovery, and affected detections.
Owner
Source owners and SIEM quality owner
Deadline
30 minutes
Question
Which fictional evidence, owner actions, validation, residual risk, and reopen conditions are required before closure?
Evidence needed
Authorization, role and group state, sessions, service impact, source recovery, validation, and approvals.
Owner
Case owner with identity, service, source, and risk owners
Deadline
Before closure
Capstone Stage 8
Supporting evidence
Extension source is delayed and current SIEM evidence may be incomplete.
Contradicting evidence
Identity owner initially sees no current extension and the visible change ended earlier.
Next evidence
Source-side extension record with event time, scope, owner, and approval authority.
Decision effect
Could move the case to Expected only if every scope and timing field matches.
Supporting evidence
Group source is Degraded and reports delayed synchronization.
Contradicting evidence
Role and session sources remain Healthy and show continuing activity.
Next evidence
Source-side group state, expected synchronization duration, event times, and recovery status.
Decision effect
May explain effective-access delay without proving authorization.
Supporting evidence
A recovery change exists and the identity has a temporary recovery role.
Contradicting evidence
The change ended before the session and covers a different destination.
Next evidence
Change-owner clarification and any additional approved record.
Decision effect
Currently a partial explanation only.
Supporting evidence
Criticality or ownership may have changed.
Contradicting evidence
Current service source and catalog agree on the relationship.
Next evidence
Service-owner confirmation and catalog review date.
Decision effect
Could adjust severity or routing but not the role and session timing.
Supporting evidence
One source is recovering and delayed delivery exists.
Contradicting evidence
Role and session records have distinct event IDs and current event times.
Next evidence
Uniqueness, replay markers, event IDs, collection paths, and source-owner review.
Decision effect
May reduce alert count but not remove the underlying condition.
Capstone Stage 9
Trigger
Privileged role and session remain active after expiration while authorization is unresolved.
Level
Level 3 time-sensitive mission escalation
Recipient
Identity owner and access-governance owner
Bounded question
Was there a valid matching extension, and what is the current role, group, and effective-access state?
Acceptance criteria
Receiving owner confirms the question, deadline, evidence boundary, and authority to answer.
Trigger
Extension and group evidence are delayed and affect authorization confidence.
Level
Level 2 multi-owner coordination
Recipient
Extension-source owner, group-source owner, and SIEM quality owner
Bounded question
Which periods and conclusions are affected, when will evidence recover, and what alternate evidence is available?
Acceptance criteria
Receiving owner confirms the question, deadline, evidence boundary, and authority to answer.
Trigger
A critical service is involved and active impact remains unconfirmed.
Level
Level 2 multi-owner coordination
Recipient
Service owner and recovery owner
Bounded question
Did the activity affect availability, users, privacy, configuration state, or recovery?
Acceptance criteria
Receiving owner confirms the question, deadline, evidence boundary, and authority to answer.
Trigger
Use only for owner nonresponse, active impact, broad scope, privacy concern, resource conflict, or residual-risk acceptance beyond operational authority.
Level
Level 4 leadership or risk decision
Recipient
Program owner, risk owner, or privacy authority
Bounded question
Which resource, priority, risk acceptance, or governance decision is required?
Acceptance criteria
Receiving owner confirms the question, deadline, evidence boundary, and authority to answer.
Capstone Stage 10
08:15
Change start
Fictional recovery change begins for database reconciliation.
State: Expected within documented scope.
08:55
Change end
Approved recovery change window ends.
State: Later session falls outside the change window.
08:58
Role event
Temporary recovery role remains Active.
State: Role assignment active near expiration.
09:00
Approval end
Approved role window ends.
State: Extension evidence required.
09:02
Group event
Group source records Active membership with delayed synchronization.
State: Effective-access confidence Conditional.
09:04
Session event
Session reaches coordination-admin after approval_end.
State: Time-sensitive stale-authority question supported.
09:07
Service event
Service remains available with no confirmed user impact.
State: Potential severity High; active impact unconfirmed.
09:08
Alert
SIEM creates the fictional stale-authority alert.
State: New.
09:10
Triage
Analyst creates neutral observation and primary question.
State: In Review.
09:15
Owner requests
Identity, source, and service owners receive bounded requests.
State: Conditional and High priority.
09:31
Escalation
Identity owner misses the initial deadline while session remains active.
State: Escalated Level 3.
09:38
Authorized action
Identity owner initiates approved role revocation.
State: Action initiated; outcome not yet validated.
09:44
Validation
Role source reports Revoked and session source reports Closed.
State: Immediate active condition ended.
09:49
Source recovery
Extension source enters Recovering and historical records arrive.
State: Historical authorization unresolved.
10:12
Recovered evidence
Recovered record shows no valid matching extension.
State: Authorization conclusion strengthens.
10:18
Service validation
Service owner confirms no user impact or validated configuration change.
State: No confirmed active service impact.
10:25
Case decision
Case moves from Escalated to Conditional pending group reconciliation and residual-risk review.
State: Conditional.
Capstone Stage 11
09:10 — Case opened for a fictional role and session remaining Active after approval_end. Extension evidence is delayed, group evidence is Degraded, and service impact is not confirmed.
09:12 — Healthy role and session evidence support activity after expiration. These records do not prove authorization, harmful intent, privileged modification, complete scope, or service impact.
09:13 — Group source Degraded and extension source Conditional. No-visible extension is interpreted as Unknown until recovery and validation complete.
09:14 — Valid delayed extension, synchronization delay, and partial recovery-change context remain unconfirmed alternatives with named owners and next evidence.
09:31 — Level 3 identity escalation activated because privileged role and session remain Active after expiration and the owner deadline was missed. Case owner retains coordination.
09:38 — Identity owner initiated approved role revocation. Action completion does not prove group reconciliation, session closure, service impact resolution, or historical authorization.
09:44 — Role source reports Revoked and session source reports Closed. Immediate active condition ended. Group and extension sources remain in recovery.
10:12 — Recovered extension evidence shows no matching approval for the observed service, destination, and period. Historical authorization confidence increases.
10:18 — Service owner confirms no current user impact, no error increase, and no validated configuration change. This does not erase the stale-authority condition.
10:25 — Case moves from Escalated to Conditional. Immediate authority and session condition ended; group reconciliation, residual risk, closure, and reopen criteria remain open.
Capstone Stage 12
Observation
The fictional rule created six raw alerts but only two unique analyst work items.
Quality question
Are duplicates caused by replay, retries, or meaningful repeated sessions?
Decision
Preserve raw count and unique work separately.
Observation
Two required fictional sources were Degraded or Conditional during the alert period.
Quality question
Which conclusions and metrics are affected?
Decision
Mark authorization metrics Conditional until recovery.
Observation
The fictional case reached first review in two minutes but owner response exceeded deadline.
Quality question
Is delay caused by analyst queue, ownership, or specialist capacity?
Decision
Track analyst delay and owner delay separately.
Observation
Identity escalation was timely, but service-impact ownership was assigned later.
Quality question
Did all bounded questions receive the correct owner at escalation time?
Decision
Improve handoff completeness.
Observation
Fictional notes preserve evidence layers, actions, validation, and unresolved closure conditions.
Quality question
Can another reviewer reconstruct every major decision?
Decision
Pass with one open source-reconciliation gap.
Observation
Replay creates duplicate raw alerts, but a changed destination must remain a grouping break.
Quality question
Can duplicate work be reduced without hiding new scope?
Decision
Test narrow deduplication in shadow mode.
Capstone Stage 13
| Field | Fictional value |
|---|---|
| Quality problem | Fictional recovery replay creates duplicate raw alerts for the same event and increases analyst workload. |
| Root cause | Duplicate delivery during source recovery, not the stale-authority defender question itself. |
| Proposed change | Deduplicate only records with identical event ID, session ID, destination, result, event time, and recovery-replay marker. |
| Break conditions | New identity, session, destination, service, result, severity, source-health state, scope, or event time remains visible. |
| Expected benefit | Reduce duplicate work while preserving all unique stale-authority questions. |
| False-negative risk | Over-deduplication could hide repeated distinct sessions or changed destinations. |
| Validation | Positive duplicate, distinct repeat, changed destination, second session, source recovery, boundary, regression, and rollback cases. |
| Rollout | Fictional shadow comparison followed by limited staged rollout after all quality gates pass. |
| Rollback | Return to the last validated grouping state when any break-condition test fails. |
| Owner | Detection-quality owner with source-owner, identity-owner, and SIEM-quality review. |
| Expiration | Review after source recovery changes, service redesign, identity-model change, or ninety days. |
| Residual risk | Unknown future replay patterns may require additional uniqueness rules and monitoring. |
Capstone Stage 14
Fictional evidence
Recovered fictional extension evidence confirms no valid matching extension after approval_end.
Status
Complete
Fictional evidence
Role source reports Revoked; group reconciliation remains incomplete.
Status
Conditional
Fictional evidence
Observed session reports Closed; no additional sessions found in currently healthy evidence.
Status
Complete with source-health limitation
Fictional evidence
Service owner and Healthy service source report no current impact or validated configuration change.
Status
Complete
Fictional evidence
Extension source recovered; group source remains Recovering.
Status
Incomplete
Fictional evidence
Role revocation and session closure validated through fictional source evidence.
Status
Complete
Fictional evidence
Group reconciliation and quality-improvement follow-up require owners and review dates.
Status
Incomplete
Fictional evidence
New session, changed destination, failed validation, conflicting recovered evidence, or repeated stale authority.
Status
Complete
Capstone Stage 15
| Case | Type | Fictional input | Expected result | Quality protected |
|---|---|---|---|---|
| CAP-T01 | Healthy expected case | Current matching extension, healthy sources, expected destination, active owner, and no impact. | Expected or low-priority review with expiration and break conditions. | Expected-activity accuracy |
| CAP-T02 | Expired role and active session | Role and session remain active after approval_end with no valid extension. | High-priority time-sensitive triage and identity escalation. | Stale-authority visibility |
| CAP-T03 | Delayed extension source | No extension visible while source is Conditional. | Authorization remains Unknown or Conditional; no false absence claim. | Source-health honesty |
| CAP-T04 | Broad Blind period | Session source is Blind during the key period. | Source-Degraded or Unknown with alternate evidence and reassessment. | False-confidence prevention |
| CAP-T05 | Current impact | Healthy service evidence confirms broad user disruption. | Increase priority and activate service plus recovery escalation. | Mission-impact response |
| CAP-T06 | Partial change match | Change matches identity and purpose but not time or destination. | Keep as a partial alternative; do not mark Expected. | Authorization scope accuracy |
| CAP-T07 | Duplicate replay | Several records share identical event, session, destination, result, and replay marker. | Group as one work item while preserving delivery history. | Workload reduction |
| CAP-T08 | Changed destination | A new destination appears inside a grouped stale-authority case. | Break grouping and reassess scope, severity, priority, and owners. | Widening-scope visibility |
| CAP-T09 | Owner nonresponse | Identity owner misses the deadline while the privileged session remains active. | Activate aging and alternate-owner paths without treating nonresponse as proof. | Time-sensitive accountability |
| CAP-T10 | Action without validation | Role revocation is initiated but group and session state are not checked. | Keep the case open and separate action from outcome. | Closure quality |
| CAP-T11 | Recovered conflicting evidence | After closure, recovery reveals a second session or extension mismatch. | Reopen the original case and preserve chronology. | Historical continuity |
| CAP-T12 | Public portfolio | Student plans to reuse sanitized real alert screenshots and timelines. | Portfolio validation fails; every detail must be invented. | Confidentiality and safety |
Leadership Communication
A fictional temporary recovery role and session remained active after approval_end. Delayed extension and group evidence limited early authorization confidence.
The identity had temporary privileged authority associated with a critical student-support service, creating high potential consequence and a short review window.
Analysts prioritized the case, escalated identity and source questions, preserved source-health limits, and coordinated authorized role revocation plus session validation.
Recovered extension evidence showed no valid matching extension. Role and observed session were later validated as ended.
No harmful intent, privileged modification, broad scope, or current service impact was established.
Group-source reconciliation, residual-risk ownership, quality-improvement validation, and final closure review remain incomplete.
Maintain the case as Conditional until source reconciliation and residual-risk criteria pass; approve only narrow replay deduplication after full regression testing.
Fake Dashboard
Fictional source health, alert quality, priority, owner deadlines, case state, closure readiness, tuning validation, and residual risk for training only.
Current fictional case state
Conditional
Immediate active condition ended, but group-source reconciliation and residual-risk ownership remain incomplete.
Open fictional owner and evidence obligations
4
Group reconciliation, quality validation, residual-risk assignment, and final closure review remain open.
Capstone quality gates passed
9 / 12
Closure, source recovery, and tuning coverage-preservation gates remain incomplete.
Fake SOC Alert
Source: Fake Northbridge SIEM Governance Console • Time: 6:12 PM
Fake Log Panel
08:58 ROLE state='active' 09:00 APPROVAL state='expired' 09:02 GROUP state='active' health='degraded' 09:04 SESSION state='active' service='critical' 09:07 IMPACT service='none-confirmed' 09:08 ALERT state='new' 09:10 CASE state='in-review' 09:13 SOURCE extension='conditional' 09:15 REQUEST identity='sent' 09:15 REQUEST source='sent' 09:15 REQUEST service='sent' 09:31 ESCALATION level='3' 09:38 ACTION role-revocation='initiated' 09:44 VALIDATION role='revoked' 09:44 VALIDATION session='closed' 09:49 SOURCE extension='recovering' 10:12 EVIDENCE extension='no-valid-match' 10:18 IMPACT service='none-confirmed' 10:25 CASE state='conditional' 18:12 CLOSURE readiness='incomplete'
Training note: this is fake data for defensive analysis practice only.
Fictional Evidence Matrix
Observation
Role and session remain Active after approval_end.
Supports
A stale-authority review is justified.
Does not prove
Does not prove harmful intent, unauthorized use, or service impact.
Capstone use
Set High priority with bounded authorization questions.
Observation
Extension source is Conditional and delayed.
Supports
Authorization absence cannot be confirmed at alert time.
Does not prove
Does not prove a valid extension exists.
Capstone use
Keep authorization confidence Moderate and request source-side evidence.
Observation
Group source is Degraded and reports Active membership.
Supports
Effective-access state may remain active but confidence is limited.
Does not prove
Does not prove exact access state for the full period.
Capstone use
Assign source-health ownership and keep the case Conditional.
Observation
Critical service remains available with no confirmed current impact.
Supports
Active service impact is not currently supported.
Does not prove
Does not remove authority, privacy, or evidence concerns.
Capstone use
Keep severity and active impact separate.
Observation
Recovery change exists but ends earlier and covers a different destination.
Supports
The change provides partial context only.
Does not prove
Does not prove the later session was unauthorized.
Capstone use
Keep as an alternative requiring owner review.
Observation
No valid matching extension exists for the observed period and destination.
Supports
Historical authorization confidence increases.
Does not prove
Does not prove intent or privileged modification.
Capstone use
Support the stale-authority conclusion and corrective-action review.
Observation
Role source reports Revoked and session source reports Closed.
Supports
The immediate active condition ended.
Does not prove
Does not complete group reconciliation, historical review, residual risk, or closure.
Capstone use
Move from Escalated to Conditional rather than directly to Resolved.
Observation
Replay creates duplicate raw alerts while changed destinations remain meaningful.
Supports
Narrow deduplication may reduce workload.
Does not prove
Does not justify broad grouping or suppression.
Capstone use
Test exact uniqueness plus break conditions in shadow mode.
Analyze the Evidence
Common Mistakes
Fictional observation
A fictional analyst writes confirmed unauthorized access before reviewing source health.
Decision impact
Unsupported certainty controls the case.
Professional correction
Begin with a neutral observation and primary defender question.
Fictional observation
A derived expired state is documented as a source-recorded value.
Decision impact
Transformation assumptions disappear.
Professional correction
Preserve source value, normalized value, transformation, and limitation.
Fictional observation
A High-severity alert is prioritized without confidence, active effect, scope, timing, or recoverability.
Decision impact
Queue decisions become inconsistent.
Professional correction
Separate severity, confidence, and priority.
Fictional observation
No-visible extension is treated as proof of no extension during delay.
Decision impact
Missing evidence becomes false absence.
Professional correction
Use Conditional, Source-Degraded, or Unknown states.
Fictional observation
The case is sent to several teams with no bounded request.
Decision impact
Ownership and response quality weaken.
Professional correction
Assign separate identity, source, service, and leadership questions.
Fictional observation
The case closes immediately after role revocation begins.
Decision impact
Sessions, group state, source recovery, validation, and residual risk remain unresolved.
Professional correction
Separate action, validation, outcome, closure, and reopening.
Fictional observation
All stale-role alerts are suppressed during source recovery.
Decision impact
Meaningful stale authority may disappear.
Professional correction
Repair the source and test narrow deduplication or expected handling.
Fictional observation
A tuning proposal passes because volume falls.
Decision impact
Changed destinations, second sessions, and false-negative risk may be hidden.
Professional correction
Require uniqueness, coverage, regression, and rollback tests.
Fictional observation
A briefing claims an incident was prevented even though only stale authority was confirmed.
Decision impact
Risk and program performance are misrepresented.
Professional correction
Separate confirmed facts, unresolved questions, actions, outcomes, and residual risk.
Fictional observation
A portfolio package includes sanitized real alerts, screenshots, owner messages, or timelines.
Decision impact
Sensitive systems, people, suppliers, priorities, and methods may be exposed.
Professional correction
Invent every organization, record, alert, identity, service, owner, date, decision, action, and outcome.
Safe Fictional Capstone Lab
Document the fictional mission, service, stakeholders, identity model, evidence sources, privacy boundary, and fictionalization statement.
Required output
Mission and safety charter
Quality gate
No real organization, system, identity, address, screenshot, or alert appears.
Classify identity, role, group, extension, session, service, change, and source-health evidence.
Required output
Source inventory and health matrix
Quality gate
Every conclusion shows which health conditions support or limit it.
Preserve source values, document transformations, join relationships, and overlay service, change, and health context.
Required output
Normalization and correlation workbook
Quality gate
Derived context is never presented as direct evidence.
Write observation, question, evidence, health behavior, severity, confidence, priority, alternatives, non-proof statements, owners, and triggers.
Required output
Complete alert contract
Quality gate
The alert states what it supports and does not prove.
Build authorization, effective-access, service, impact, source-health, scope, alternative, ownership, and closure questions.
Required output
Question map and evidence requests
Quality gate
Every request is purpose-limited, owned, time-bounded, and decision-linked.
Evaluate potential consequence, certainty, active effect, time sensitivity, scope, recoverability, ownership, and source health.
Required output
Severity-confidence-priority record
Quality gate
The three concepts remain separate.
Assign escalation types, levels, owners, deadlines, acceptance, chronology, notes, decisions, actions, validation, and states.
Required output
Escalation and case package
Quality gate
One coordinating owner preserves the complete case.
Evaluate volume, uniqueness, source health, queue age, owner delay, case quality, coverage, workload, privacy, and residual risk.
Required output
Decision-oriented dashboard review
Quality gate
Averages, denominators, duplicates, and blind periods are addressed.
Classify replay duplication, propose narrow deduplication, define breaks, test in shadow mode, assign rollback, and document expiration.
Required output
Tuning and rollback package
Quality gate
Lower count cannot pass when coverage tests fail.
Review authorization, scope, impact, validation, source health, residual risk, closure, reopening, and leadership decisions.
Required output
Closure review and leadership brief
Quality gate
The case cannot close while required source or risk obligations remain incomplete.
Scenario Decision Lab
Fictional Northbridge validates role revocation and session closure, but extension and group sources are still Recovering. No current service impact is confirmed.
Scenario Decision Lab
A fictional deduplication proposal reduces raw alerts by 60%, but shadow testing shows a changed destination is grouped into the original case.
Advanced Challenge
Present the fictional Northbridge case as though a review board asks why the alert existed, why priority was High, why the case escalated, why the conclusion remained Conditional, why source health mattered, why the case did not close after revocation, and why narrow deduplication is safer than broad suppression.
Defend the evidence chain
Explain raw evidence, parsing, normalization, enrichment, correlation, provenance, timing, source health, and limitations.
Defend the alert
Explain observation, defender question, required evidence, severity, confidence, priority, alternatives, and non-proof statements.
Defend triage and escalation
Explain questions, owners, deadlines, source-health limits, escalation types, levels, acceptance, aging, and de-escalation.
Defend the case
Explain chronology, notes, hypotheses, decisions, actions, validation, state changes, residual uncertainty, and reopening.
Defend the metrics
Explain volume, uniqueness, queue age, owner delay, source health, quality, coverage, workload, privacy, recovery, and residual risk.
Defend quality improvement
Explain root cause, narrow deduplication, break conditions, shadow mode, regression, rollback, expiration, ownership, and residual risk.
Challenge output
Produce a fictional mission charter, source inventory, source-health matrix, evidence ledger, normalization map, correlation model, alert contract, severity-confidence-priority record, triage question map, alternative matrix, escalation plan, chronology, case notes, dashboard review, metric dictionary, tuning proposal, validation matrix, rollback plan, closure review, residual-risk record, leadership brief, and public portfolio boundary.
Defender Habits
Check Your Understanding
Choose your answers first. Explanations appear only after submission.
Portfolio Prompt
Create a fully fictional SIEM Triage Capstone Package for the Northbridge Student-Support Cooperative. Include mission, stakeholders, critical service, identity model, source inventory, source IDs, source roles, required fields, source owners, source-health states, raw evidence IDs, event times, collection times, processing times, source records, supports, non-proof statements, parsed fields, normalized fields, enrichment, derived context, transformations, mapping risks, correlations, alert title, primary defender question, neutral observation, required evidence, severity, confidence, priority, alternatives, review triggers, triage questions, evidence requests, owners, deadlines, escalation types, escalation levels, acceptance criteria, chronology, case notes, hypotheses, decisions, actions, validation, state changes, dashboard reviews, metrics, tuning root cause, proposed change, break conditions, validation cases, shadow comparison, rollout, rollback, expiration, closure criteria, residual uncertainty, residual risk, reopen triggers, leadership brief, advanced challenge, reflection, and a statement that every organization, record, alert, identity, service, owner, date, decision, action, metric, and outcome is invented.
Confidence / Readiness Reflection
Rate your readiness from 1 to 5 for SIEM purpose, source inventory, collection, normalization, correlation, alert rules, severity, confidence, priority, triage questions, evidence review, escalation, case notes, dashboards, metrics, noise reduction, tuning, validation, rollback, closure, reopening, and complete fictionalization.
Key Takeaways
Navigation
You have completed all ten A6 lessons. Next, take the A6 Module Test covering SIEM purpose, collection, normalization, correlation, severity, priority, triage, escalation, case management, dashboards, metrics, quality improvement, and the capstone workflow.