High School AdvancedModule A6Lesson 10 of 10Full SIEM and Alert-Triage Capstone

A6.10 SIEM Triage Lab

Complete an end-to-end fictional defensive investigation using log collection, normalization, correlation, alert design, severity, priority, triage questions, evidence review, escalation, case management, dashboards, metrics, tuning, rollback, closure, and reopening.

Lesson Progress

SIEM Triage Lab

High School AdvancedA6: SIEM and Alert Triage Concepts • Lesson 10 of 10

100% complete

Readiness Check

Before You Start

0/6 ready

Professional Hook

A Strong Triage Decision Can Remain Conditional

Fictional Northbridge has strong evidence that a temporary role and session continued after expiration. Yet extension evidence is delayed, group evidence is Degraded, service impact is not confirmed, and recovery is incomplete. The professional goal is not to force a dramatic final label. It is to make the strongest evidence-supported decision, assign the right owners, preserve the right uncertainty, and define exactly what must happen next.

Weak conclusion

“The SIEM proved malicious privileged access and the identity team fixed it.”

Strong conclusion

“The SIEM supported stale authority and active session evidence after expiration. Authorized revocation ended the immediate condition. Historical authorization, group reconciliation, residual risk, and closure remain under review.”

Advanced defensive work values accurate uncertainty more than impressive certainty.

Exactly Five Learning Objectives

What You Will Be Able to Do

Objective 1

Conduct a complete fictional SIEM triage workflow from alert intake through evidence review, prioritization, escalation, case management, quality improvement, closure, and reopening.

Objective 2

Reconstruct fictional evidence using source health, event time, collection time, processing time, normalization, enrichment, correlation, provenance, limitations, and alternative explanations.

Objective 3

Assign fictional severity, confidence, priority, owners, deadlines, escalation levels, case states, validation requirements, closure criteria, and reopen triggers.

Objective 4

Evaluate fictional alert noise, duplicate delivery, grouping, thresholds, expected activity, source defects, false-positive risk, false-negative risk, rollback, and coverage preservation.

Objective 5

Create a portfolio-ready fictional SIEM Triage Capstone Package containing an alert contract, evidence matrix, chronology, triage record, escalation plan, case notes, dashboard review, tuning proposal, leadership brief, residual-risk record, and reflection.

Why This Matters

SIEM Work Is a Chain of Evidence and Decisions

Fictional SIEM work fails when teams treat logs, alerts, severity, priority, triage, escalation, notes, dashboards, and tuning as separate activities. A parser defect can distort normalization. A normalization defect can distort correlation. A correlation defect can distort severity. A priority error can delay review. A weak note can hide uncertainty. A bad metric can reward premature closure. A broad tuning change can hide the next important condition.

Evidence chain

Sources, parsing, normalization, enrichment, correlation, timing, health, and provenance must remain traceable.

Decision chain

Severity, confidence, priority, state, escalation, actions, closure, and reopening must remain evidence-supported.

Improvement chain

Metrics, tuning, validation, rollback, ownership, debt, residual risk, and review must preserve mission coverage.

Capstone Framework

The S-I-E-M C-A-S-E Method

S — Sources and safety

Define mission, evidence sources, source health, owners, privacy, retention, and non-operational boundaries.

I — Interpret and normalize

Preserve source values, parsed fields, normalized values, enrichment, transformations, timing, and limitations.

E — Evaluate correlation

Join identity, role, group, extension, session, service, destination, change, owner, and health relationships.

M — Make the alert meaningful

Document observation, primary question, evidence, non-proof statements, severity, confidence, priority, alternatives, and triggers.

C — Conduct triage

Ask authorization, effective-access, service, impact, source-health, scope, alternative, ownership, and closure questions.

A — Assign escalation and action

Name owners, levels, deadlines, handoff acceptance, authorized actions, validation, and de-escalation criteria.

S — Sustain the case

Maintain chronology, notes, evidence ledger, decisions, state changes, residual uncertainty, closure, and reopening.

E — Evolve quality

Use dashboards, metrics, root cause, tuning, break conditions, shadow comparison, rollback, debt, and lifecycle review.

Advanced Vocabulary

Capstone Terms

Capstone triage

A fictional end-to-end defensive review combining alert interpretation, evidence analysis, source health, prioritization, escalation, case management, quality improvement, closure, and reopening.

Alert contract

A fictional statement of what an alert observes, which evidence it requires, how source health affects it, what it does not prove, and which defender question it supports.

Correlation bundle

A fictional set of related normalized records joined by identity, device, service, destination, session, approval, timing, owner, or source-health relationships.

Evidence provenance

A fictional record of where evidence originated, how it was parsed, normalized, enriched, transformed, and used.

Evidence confidence

A fictional judgment about how reliable and complete available evidence is for a specific conclusion.

Severity

A fictional estimate of potential consequence if the observed condition is meaningful.

Priority

A fictional decision about review urgency using severity, confidence, active effect, scope, source health, time sensitivity, ownership, and recoverability.

Triage question map

A fictional register of observation, authorization, effective-access, service, source-health, scope, impact, alternatives, ownership, and closure questions.

Escalation level

A fictional classification describing routine, specialist, multi-owner, time-sensitive mission, or leadership review.

Case state

A fictional lifecycle label such as New, In Review, Conditional, Expected, Source-Degraded, Unknown, Escalated, Resolved, or Reopened.

Break condition

A fictional change that prevents grouping, expected handling, or suppression from hiding meaningful identity, session, destination, service, severity, source-health, timing, scope, owner, or result differences.

Quality gate

A fictional required validation check before a rule, tuning change, state transition, escalation exit, or closure decision is approved.

Residual uncertainty

A fictional important question or evidence limitation that remains unresolved after the current review.

Residual risk

A fictional risk that remains after approved actions, validation, and decisions are complete.

Closure criterion

A fictional documented requirement that must be satisfied before a case can be resolved.

Reopen trigger

A fictional new-evidence, failed-validation, changed-scope, repeated-behavior, source-recovery, or residual-risk condition requiring renewed review.

Capstone Context

Fictional Northbridge Organization

Organization

Northbridge Student-Support Cooperative, a completely invented educational support organization.

Mission

Provide reliable scheduling, counseling coordination, resource referrals, and family-support workflows for fictional partner schools.

Critical service

Student Assistance Coordination Service, used by fictional staff to manage time-sensitive support referrals.

Identity model

Permanent staff roles, temporary recovery roles, supplier support assignments, and service-owner approvals.

Evidence model

Fictional identity, role, group, approval, extension, session, service, destination, change, source-health, and case records.

Safety boundary

Every organization, identity, field, record, service, owner, date, alert, action, decision, and outcome is invented and non-operational.

Capstone Stage 1

Review Eight Fictional Evidence Sources

SRC-01

Identity directory

Healthy

Provides fictional identity category, sponsor, owner, and lifecycle state.

Required fields

identity_id, identity_category, lifecycle_state, sponsor_id, owner_role, event_time

Limitation

Does not prove current role assignment, effective access, or session activity.

SRC-02

Role-governance source

Healthy

Provides fictional role assignment, approval, extension, revocation, purpose, and scope.

Required fields

identity_id, role_category, role_state, approval_start, approval_end, purpose, scope, event_time

Limitation

Role assignment does not prove current group membership or exercised access.

SRC-03

Group-state source

Degraded

Provides fictional effective group membership and synchronization state.

Required fields

identity_id, group_category, membership_state, sync_state, event_time

Limitation

Delayed synchronization makes exact effective access uncertain.

SRC-04

Extension-approval source

Conditional

Provides fictional time-bounded emergency-role extensions.

Required fields

identity_id, role_category, extension_id, extension_start, extension_end, approver_role, scope, event_time

Limitation

Ingestion delay may hide a valid extension or delay proof that none exists.

SRC-05

Session source

Healthy

Provides fictional session, identity, device, service, destination, operation category, result, start, and end.

Required fields

session_id, identity_id, device_category, service_id, destination_category, operation_category, result, event_time

Limitation

A session does not prove harmful intent or privileged modification.

SRC-06

Service-health source

Healthy

Provides fictional availability, error, user-impact, dependency, and recovery states.

Required fields

service_id, availability_state, error_state, impact_category, recovery_state, event_time

Limitation

Normal availability does not prove access was authorized or necessary.

SRC-07

Change-management source

Healthy

Provides fictional maintenance, migration, recovery, owner, start, end, scope, and validation.

Required fields

change_id, owner_role, purpose, scope, start_time, end_time, expected_behavior, validation_state

Limitation

A change explains only activity matching its exact scope and time.

SRC-08

SIEM source-health source

Healthy

Provides fictional freshness, completeness, schema, parser, queue, blind-period, conflict, replay, and recovery state.

Required fields

source_id, health_state, affected_period, freshness, completeness, schema_state, parser_state, recovery_state

Limitation

Health metadata describes evidence quality, not the underlying activity.

Capstone Stage 2

Inspect Eight Raw Evidence Records

RAW-01

Role-governance source

Event time

08:58

Collection time

08:59

Processing time

09:00

Fictional record

identity_id=NB-ID-042; role_category=temporary-recovery; role_state=Active; approval_end=09:00; purpose=service-recovery

Supports

The fictional role remained assigned near the approved end time.

Does not prove

Does not prove a valid extension, effective group access, session activity, misuse, or service impact.

RAW-02

Group-state source

Event time

09:02

Collection time

09:11

Processing time

09:12

Fictional record

identity_id=NB-ID-042; group_category=recovery-admin; membership_state=Active; sync_state=Delayed

Supports

Fictional effective group membership may still be active.

Does not prove

Delayed evidence does not establish the exact state at every minute.

RAW-03

Extension-approval source

Event time

08:54

Collection time

09:18

Processing time

09:19

Fictional record

identity_id=NB-ID-042; role_category=temporary-recovery; extension_state=None-Visible; source_delay=24-minutes

Supports

No extension is visible in the fictional SIEM at processing time.

Does not prove

The delay prevents a confident source-side absence conclusion.

RAW-04

Session source

Event time

09:04

Collection time

09:05

Processing time

09:06

Fictional record

session_id=NB-SES-881; identity_id=NB-ID-042; service_id=NB-SVC-07; destination_category=coordination-admin; operation_category=configuration-review; result=Success

Supports

One fictional session continued after approval_end and reached the critical service.

Does not prove

Does not prove unauthorized use, harmful intent, privileged modification, or user impact.

RAW-05

Service-health source

Event time

09:07

Collection time

09:08

Processing time

09:09

Fictional record

service_id=NB-SVC-07; availability_state=Normal; error_state=No-Increase; impact_category=None-Confirmed; recovery_state=Stable

Supports

No current fictional service disruption is confirmed.

Does not prove

Normal service health does not prove the activity was expected or authorized.

RAW-06

Change-management source

Event time

08:20

Collection time

08:21

Processing time

08:22

Fictional record

change_id=NB-CHG-114; purpose=service-recovery; scope=database-reconciliation; start=08:15; end=08:55; destination=coordination-database

Supports

A fictional approved recovery change existed before the alert.

Does not prove

The change ended before the observed session and covers a different destination.

RAW-07

SIEM source-health source

Event time

09:00

Collection time

09:00

Processing time

09:01

Fictional record

source_id=SRC-03; health_state=Degraded; affected_period=08:50-09:25; freshness=Delayed; completeness=Conditional

Supports

Group-state evidence is not fully reliable for normal-confidence conclusions.

Does not prove

Source degradation does not prove effective access remained active or inactive.

RAW-08

SIEM source-health source

Event time

09:00

Collection time

09:00

Processing time

09:01

Fictional record

source_id=SRC-04; health_state=Conditional; affected_period=08:45-09:30; freshness=Delayed; completeness=Unknown

Supports

Extension evidence may be incomplete at alert time.

Does not prove

The source state does not prove a valid extension exists.

Capstone Stage 3

Review Six Normalization Decisions

NORM-01

Source value

role_state=Active; approval_end=09:00

Normalized value

authorization.assignment_state=active; authorization.window_state=expired

Transformation

Mapped source role state and compared approval_end with fictional event time.

Risk

The expired interpretation may change if a valid delayed extension exists.

NORM-02

Source value

membership_state=Active; sync_state=Delayed

Normalized value

access.group_state=active; evidence.group_confidence=conditional

Transformation

Preserved source state while lowering confidence because of source degradation.

Risk

Normalized Active must not become proof of exact effective access.

NORM-03

Source value

extension_state=None-Visible; source_delay=24-minutes

Normalized value

authorization.extension_state=unknown

Transformation

Converted no-visible evidence under delay into Unknown rather than None.

Risk

Mapping no-visible to no-extension would create false certainty.

NORM-04

Source value

operation_category=configuration-review; result=Success

Normalized value

activity.category=administrative-review; activity.result=success

Transformation

Mapped a source-specific operation into a shared category.

Risk

The canonical category may hide source-specific detail.

NORM-05

Source value

availability_state=Normal; impact_category=None-Confirmed

Normalized value

service.active_impact=false; service.impact_confidence=moderate

Transformation

Combined healthy service evidence with owner-independent availability fields.

Risk

No current impact does not prove no authority, privacy, or evidence risk.

NORM-06

Source value

change end=08:55; session=09:04; destination mismatch

Normalized value

change.match_state=partial

Transformation

Compared identity, time, service, destination, and purpose.

Risk

Partial match must not become full approval or full contradiction.

Capstone Stage 4

Trace Six Correlation Stages

Identity join

Logic

Join fictional role, group, extension, and session records using identity_id.

Result

One identity connects assignment, potential effective access, extension evidence, and active session.

Limitation

Identity equality does not prove the same actor controlled every record.

Role-window comparison

Logic

Compare fictional session event time with approval_end and visible extension window.

Result

Session occurs after approval_end and no valid matching extension is currently visible.

Limitation

Extension delay keeps authorization confidence below High.

Service relationship

Logic

Join fictional session destination and service catalog.

Result

Session reaches a critical student-support administrative destination.

Limitation

Criticality describes potential consequence, not current impact.

Change comparison

Logic

Compare fictional session identity, service, destination, purpose, and time with approved changes.

Result

Existing change explains recovery context but not the observed time and destination.

Limitation

The change remains a partial alternative.

Source-health overlay

Logic

Attach fictional group and extension source-health states.

Result

Observation confidence is stronger than authorization confidence.

Limitation

Missing or delayed evidence cannot become absence.

Impact overlay

Logic

Attach fictional service availability and user-impact evidence.

Result

Potential severity is High, but active service impact is not confirmed.

Limitation

No current impact does not remove authority or privacy concerns.

Capstone Stage 5

Build the Twelve-Field Alert Contract

FieldFictional value
Alert titleTemporary Recovery Role and Session Continue after Approved End
Primary defender questionDid a fictional temporary recovery identity retain effective authority or session activity beyond its current approved authorization window?
Neutral observationA fictional temporary recovery role and one session remain Active after approval_end. Extension evidence is delayed, group evidence is Degraded, and current service impact is not confirmed.
Required evidenceRole, group, extension, session, service, change, owner, timing, and source-health evidence.
SeverityHigh because privileged authority may affect a critical student-support service.
ConfidenceModerate because role and session evidence are Healthy while extension and group evidence are limited.
Initial priorityHigh because the session is active, the authorization window ended, and delay may reduce the response opportunity.
What the alert supportsA time-sensitive fictional stale-authority review involving identity, source, and service owners.
What the alert does not proveIt does not prove harmful intent, unauthorized use, privileged modification, complete scope, or current service impact.
Source-health behaviorNo-visible extension becomes Unknown when the source is delayed; missing group evidence cannot become false absence.
Expected alternativesValid delayed extension, synchronization delay, partial maintenance context, stale owner context, or incomplete recovery.
Review triggerNew session, new destination, active impact, missed owner deadline, source-health change, or scope expansion.

Capstone Stage 6

Separate Severity, Confidence, and Priority

Potential consequence

Evidence

Temporary privileged authority reaches a critical service.

Assessment

High severity.

Limitation

Potential consequence is not current impact.

Observation confidence

Evidence

Healthy role and session evidence show activity after approval_end.

Assessment

High observation confidence.

Limitation

Observation does not establish authorization.

Authorization confidence

Evidence

Extension source is Conditional and group source is Degraded.

Assessment

Moderate authorization confidence.

Limitation

No valid extension is visible, but source-side absence is not yet confirmed.

Active effect

Evidence

Service source shows Normal availability and no current error increase.

Assessment

No confirmed active service impact.

Limitation

Authority and privacy concerns may still exist.

Time sensitivity

Evidence

Session remains Active after expiration and owner responses are pending.

Assessment

High urgency.

Limitation

Urgency does not prove harmful behavior.

Scope

Evidence

One identity, one session, one critical service, and one destination are observed.

Assessment

Bounded current scope with possible wider scope unknown.

Limitation

Degraded group evidence limits complete scope.

Recoverability

Evidence

Role revocation and session closure exist through authorized owner processes.

Assessment

Potentially recoverable with validation.

Limitation

Technical action does not complete historical authorization.

Initial priority

Evidence

High severity, Moderate confidence, active session, short response window, and limited authorization evidence.

Assessment

High priority.

Limitation

Priority must change when evidence changes.

Capstone Stage 7

Create Eight Triage Questions

Q-01

Observation

Question

Which fictional records support role and session activity after approval_end?

Evidence needed

Role event, approval_end, session event, event times, source health, and correlation explanation.

Owner

Case analyst and source owners

Deadline

Immediate

Q-02

Authorization

Question

Did a valid fictional extension exist for the identity, role, service, destination, purpose, and alert period?

Evidence needed

Source-side extension record, scope, approver, start, end, purpose, and source health.

Owner

Identity owner and extension-source owner

Deadline

30 minutes

Q-03

Effective access

Question

Did fictional group membership and active sessions preserve effective authority after expiration?

Evidence needed

Group state, synchronization state, session state, device relationship, operation category, and result.

Owner

Identity owner and group-source owner

Deadline

30 minutes

Q-04

Service and impact

Question

Did the fictional activity affect service availability, users, privacy, evidence, or recovery?

Evidence needed

Service state, errors, user-impact category, owner statement, destination purpose, and recovery state.

Owner

Service owner

Deadline

45 minutes

Q-05

Alternatives

Question

Does the fictional recovery change, synchronization delay, or delayed extension fully explain the observation?

Evidence needed

Change scope, time, destination, owner, expected behavior, source health, and extension event time.

Owner

Change, identity, and source owners

Deadline

45 minutes

Q-06

Scope

Question

Are additional fictional identities, sessions, services, destinations, devices, or periods affected?

Evidence needed

Unique relationship review, duplicate handling, source coverage, service dependencies, and blind periods.

Owner

Case analyst and SIEM quality owner

Deadline

1 hour

Q-07

Source health

Question

Which conclusions are limited by fictional Degraded or Conditional evidence?

Evidence needed

Freshness, completeness, schema, parser, queue, coverage, conflict, recovery, and affected detections.

Owner

Source owners and SIEM quality owner

Deadline

30 minutes

Q-08

Closure

Question

Which fictional evidence, owner actions, validation, residual risk, and reopen conditions are required before closure?

Evidence needed

Authorization, role and group state, sessions, service impact, source recovery, validation, and approvals.

Owner

Case owner with identity, service, source, and risk owners

Deadline

Before closure

Capstone Stage 8

Compare Five Alternative Explanations

Valid extension arrived late

Supporting evidence

Extension source is delayed and current SIEM evidence may be incomplete.

Contradicting evidence

Identity owner initially sees no current extension and the visible change ended earlier.

Next evidence

Source-side extension record with event time, scope, owner, and approval authority.

Decision effect

Could move the case to Expected only if every scope and timing field matches.

Group synchronization delay

Supporting evidence

Group source is Degraded and reports delayed synchronization.

Contradicting evidence

Role and session sources remain Healthy and show continuing activity.

Next evidence

Source-side group state, expected synchronization duration, event times, and recovery status.

Decision effect

May explain effective-access delay without proving authorization.

Approved recovery activity

Supporting evidence

A recovery change exists and the identity has a temporary recovery role.

Contradicting evidence

The change ended before the session and covers a different destination.

Next evidence

Change-owner clarification and any additional approved record.

Decision effect

Currently a partial explanation only.

Stale service context

Supporting evidence

Criticality or ownership may have changed.

Contradicting evidence

Current service source and catalog agree on the relationship.

Next evidence

Service-owner confirmation and catalog review date.

Decision effect

Could adjust severity or routing but not the role and session timing.

Recovery replay

Supporting evidence

One source is recovering and delayed delivery exists.

Contradicting evidence

Role and session records have distinct event IDs and current event times.

Next evidence

Uniqueness, replay markers, event IDs, collection paths, and source-owner review.

Decision effect

May reduce alert count but not remove the underlying condition.

Capstone Stage 9

Build the Escalation Plan

Identity escalation

Trigger

Privileged role and session remain active after expiration while authorization is unresolved.

Level

Level 3 time-sensitive mission escalation

Recipient

Identity owner and access-governance owner

Bounded question

Was there a valid matching extension, and what is the current role, group, and effective-access state?

Acceptance criteria

Receiving owner confirms the question, deadline, evidence boundary, and authority to answer.

Source-health escalation

Trigger

Extension and group evidence are delayed and affect authorization confidence.

Level

Level 2 multi-owner coordination

Recipient

Extension-source owner, group-source owner, and SIEM quality owner

Bounded question

Which periods and conclusions are affected, when will evidence recover, and what alternate evidence is available?

Acceptance criteria

Receiving owner confirms the question, deadline, evidence boundary, and authority to answer.

Service-owner escalation

Trigger

A critical service is involved and active impact remains unconfirmed.

Level

Level 2 multi-owner coordination

Recipient

Service owner and recovery owner

Bounded question

Did the activity affect availability, users, privacy, configuration state, or recovery?

Acceptance criteria

Receiving owner confirms the question, deadline, evidence boundary, and authority to answer.

Leadership escalation

Trigger

Use only for owner nonresponse, active impact, broad scope, privacy concern, resource conflict, or residual-risk acceptance beyond operational authority.

Level

Level 4 leadership or risk decision

Recipient

Program owner, risk owner, or privacy authority

Bounded question

Which resource, priority, risk acceptance, or governance decision is required?

Acceptance criteria

Receiving owner confirms the question, deadline, evidence boundary, and authority to answer.

Capstone Stage 10

Reconstruct the Fictional Chronology

08:15

Change start

RAW-06

Fictional recovery change begins for database reconciliation.

State: Expected within documented scope.

08:55

Change end

RAW-06

Approved recovery change window ends.

State: Later session falls outside the change window.

08:58

Role event

RAW-01

Temporary recovery role remains Active.

State: Role assignment active near expiration.

09:00

Approval end

RAW-01

Approved role window ends.

State: Extension evidence required.

09:02

Group event

RAW-02 and RAW-07

Group source records Active membership with delayed synchronization.

State: Effective-access confidence Conditional.

09:04

Session event

RAW-04

Session reaches coordination-admin after approval_end.

State: Time-sensitive stale-authority question supported.

09:07

Service event

RAW-05

Service remains available with no confirmed user impact.

State: Potential severity High; active impact unconfirmed.

09:08

Alert

Alert contract

SIEM creates the fictional stale-authority alert.

State: New.

09:10

Triage

Q-01 through Q-08

Analyst creates neutral observation and primary question.

State: In Review.

09:15

Owner requests

Escalation plan

Identity, source, and service owners receive bounded requests.

State: Conditional and High priority.

09:31

Escalation

Escalation plan

Identity owner misses the initial deadline while session remains active.

State: Escalated Level 3.

09:38

Authorized action

Action log

Identity owner initiates approved role revocation.

State: Action initiated; outcome not yet validated.

09:44

Validation

Validation log

Role source reports Revoked and session source reports Closed.

State: Immediate active condition ended.

09:49

Source recovery

Source-health record

Extension source enters Recovering and historical records arrive.

State: Historical authorization unresolved.

10:12

Recovered evidence

Recovered approval record

Recovered record shows no valid matching extension.

State: Authorization conclusion strengthens.

10:18

Service validation

Service note

Service owner confirms no user impact or validated configuration change.

State: No confirmed active service impact.

10:25

Case decision

Decision log

Case moves from Escalated to Conditional pending group reconciliation and residual-risk review.

State: Conditional.

Capstone Stage 11

Write Ten Professional Case Notes

NOTE-01Intake

09:10 — Case opened for a fictional role and session remaining Active after approval_end. Extension evidence is delayed, group evidence is Degraded, and service impact is not confirmed.

NOTE-02Evidence

09:12 — Healthy role and session evidence support activity after expiration. These records do not prove authorization, harmful intent, privileged modification, complete scope, or service impact.

NOTE-03Source health

09:13 — Group source Degraded and extension source Conditional. No-visible extension is interpreted as Unknown until recovery and validation complete.

NOTE-04Hypotheses

09:14 — Valid delayed extension, synchronization delay, and partial recovery-change context remain unconfirmed alternatives with named owners and next evidence.

NOTE-05Escalation

09:31 — Level 3 identity escalation activated because privileged role and session remain Active after expiration and the owner deadline was missed. Case owner retains coordination.

NOTE-06Action

09:38 — Identity owner initiated approved role revocation. Action completion does not prove group reconciliation, session closure, service impact resolution, or historical authorization.

NOTE-07Validation

09:44 — Role source reports Revoked and session source reports Closed. Immediate active condition ended. Group and extension sources remain in recovery.

NOTE-08Recovered evidence

10:12 — Recovered extension evidence shows no matching approval for the observed service, destination, and period. Historical authorization confidence increases.

NOTE-09Service validation

10:18 — Service owner confirms no current user impact, no error increase, and no validated configuration change. This does not erase the stale-authority condition.

NOTE-10Decision

10:25 — Case moves from Escalated to Conditional. Immediate authority and session condition ended; group reconciliation, residual risk, closure, and reopen criteria remain open.

Capstone Stage 12

Review Six Dashboard Decisions

Alert volume

Observation

The fictional rule created six raw alerts but only two unique analyst work items.

Quality question

Are duplicates caused by replay, retries, or meaningful repeated sessions?

Decision

Preserve raw count and unique work separately.

Source health

Observation

Two required fictional sources were Degraded or Conditional during the alert period.

Quality question

Which conclusions and metrics are affected?

Decision

Mark authorization metrics Conditional until recovery.

Queue age

Observation

The fictional case reached first review in two minutes but owner response exceeded deadline.

Quality question

Is delay caused by analyst queue, ownership, or specialist capacity?

Decision

Track analyst delay and owner delay separately.

Escalation quality

Observation

Identity escalation was timely, but service-impact ownership was assigned later.

Quality question

Did all bounded questions receive the correct owner at escalation time?

Decision

Improve handoff completeness.

Case quality

Observation

Fictional notes preserve evidence layers, actions, validation, and unresolved closure conditions.

Quality question

Can another reviewer reconstruct every major decision?

Decision

Pass with one open source-reconciliation gap.

Noise and tuning

Observation

Replay creates duplicate raw alerts, but a changed destination must remain a grouping break.

Quality question

Can duplicate work be reduced without hiding new scope?

Decision

Test narrow deduplication in shadow mode.

Capstone Stage 13

Design the Twelve-Field Tuning Proposal

FieldFictional value
Quality problemFictional recovery replay creates duplicate raw alerts for the same event and increases analyst workload.
Root causeDuplicate delivery during source recovery, not the stale-authority defender question itself.
Proposed changeDeduplicate only records with identical event ID, session ID, destination, result, event time, and recovery-replay marker.
Break conditionsNew identity, session, destination, service, result, severity, source-health state, scope, or event time remains visible.
Expected benefitReduce duplicate work while preserving all unique stale-authority questions.
False-negative riskOver-deduplication could hide repeated distinct sessions or changed destinations.
ValidationPositive duplicate, distinct repeat, changed destination, second session, source recovery, boundary, regression, and rollback cases.
RolloutFictional shadow comparison followed by limited staged rollout after all quality gates pass.
RollbackReturn to the last validated grouping state when any break-condition test fails.
OwnerDetection-quality owner with source-owner, identity-owner, and SIEM-quality review.
ExpirationReview after source recovery changes, service redesign, identity-model change, or ninety days.
Residual riskUnknown future replay patterns may require additional uniqueness rules and monitoring.

Capstone Stage 14

Evaluate Eight Closure Criteria

Primary question answered

Fictional evidence

Recovered fictional extension evidence confirms no valid matching extension after approval_end.

Status

Complete

Role and effective access resolved

Fictional evidence

Role source reports Revoked; group reconciliation remains incomplete.

Status

Conditional

Sessions resolved

Fictional evidence

Observed session reports Closed; no additional sessions found in currently healthy evidence.

Status

Complete with source-health limitation

Service impact reviewed

Fictional evidence

Service owner and Healthy service source report no current impact or validated configuration change.

Status

Complete

Source health reconciled

Fictional evidence

Extension source recovered; group source remains Recovering.

Status

Incomplete

Actions validated

Fictional evidence

Role revocation and session closure validated through fictional source evidence.

Status

Complete

Residual risk assigned

Fictional evidence

Group reconciliation and quality-improvement follow-up require owners and review dates.

Status

Incomplete

Reopen triggers documented

Fictional evidence

New session, changed destination, failed validation, conflicting recovered evidence, or repeated stale authority.

Status

Complete

Capstone Stage 15

Validate Twelve End-to-End Scenarios

CaseTypeFictional inputExpected resultQuality protected
CAP-T01Healthy expected caseCurrent matching extension, healthy sources, expected destination, active owner, and no impact.Expected or low-priority review with expiration and break conditions.Expected-activity accuracy
CAP-T02Expired role and active sessionRole and session remain active after approval_end with no valid extension.High-priority time-sensitive triage and identity escalation.Stale-authority visibility
CAP-T03Delayed extension sourceNo extension visible while source is Conditional.Authorization remains Unknown or Conditional; no false absence claim.Source-health honesty
CAP-T04Broad Blind periodSession source is Blind during the key period.Source-Degraded or Unknown with alternate evidence and reassessment.False-confidence prevention
CAP-T05Current impactHealthy service evidence confirms broad user disruption.Increase priority and activate service plus recovery escalation.Mission-impact response
CAP-T06Partial change matchChange matches identity and purpose but not time or destination.Keep as a partial alternative; do not mark Expected.Authorization scope accuracy
CAP-T07Duplicate replaySeveral records share identical event, session, destination, result, and replay marker.Group as one work item while preserving delivery history.Workload reduction
CAP-T08Changed destinationA new destination appears inside a grouped stale-authority case.Break grouping and reassess scope, severity, priority, and owners.Widening-scope visibility
CAP-T09Owner nonresponseIdentity owner misses the deadline while the privileged session remains active.Activate aging and alternate-owner paths without treating nonresponse as proof.Time-sensitive accountability
CAP-T10Action without validationRole revocation is initiated but group and session state are not checked.Keep the case open and separate action from outcome.Closure quality
CAP-T11Recovered conflicting evidenceAfter closure, recovery reveals a second session or extension mismatch.Reopen the original case and preserve chronology.Historical continuity
CAP-T12Public portfolioStudent plans to reuse sanitized real alert screenshots and timelines.Portfolio validation fails; every detail must be invented.Confidentiality and safety

Leadership Communication

Write the Seven-Part Leadership Brief

What happened

A fictional temporary recovery role and session remained active after approval_end. Delayed extension and group evidence limited early authorization confidence.

Why it mattered

The identity had temporary privileged authority associated with a critical student-support service, creating high potential consequence and a short review window.

What defenders did

Analysts prioritized the case, escalated identity and source questions, preserved source-health limits, and coordinated authorized role revocation plus session validation.

What was confirmed

Recovered extension evidence showed no valid matching extension. Role and observed session were later validated as ended.

What was not confirmed

No harmful intent, privileged modification, broad scope, or current service impact was established.

What remains open

Group-source reconciliation, residual-risk ownership, quality-improvement validation, and final closure review remain incomplete.

Decision needed

Maintain the case as Conditional until source reconciliation and residual-risk criteria pass; approve only narrow replay deduplication after full regression testing.

Fake Dashboard

Fake Northbridge SIEM Triage Capstone Dashboard

Fictional source health, alert quality, priority, owner deadlines, case state, closure readiness, tuning validation, and residual risk for training only.

Current fictional case state

Conditional

Immediate active condition ended, but group-source reconciliation and residual-risk ownership remain incomplete.

Open fictional owner and evidence obligations

4

Group reconciliation, quality validation, residual-risk assignment, and final closure review remain open.

Capstone quality gates passed

9 / 12

Closure, source recovery, and tuning coverage-preservation gates remain incomplete.

Fake SOC Alert

Capstone Closure Is Not Yet Supported

Source: Fake Northbridge SIEM Governance Console • Time: 6:12 PM

High Severity
The fictional role is Revoked and the observed session is Closed. Recovered extension evidence shows no valid matching extension, but group-source reconciliation, residual-risk ownership, tuning regression, and final closure approval remain incomplete.
Defensive recommendation: Keep the fictional case Conditional. Complete group-source recovery, residual-risk assignment, tuning coverage validation, closure review, and documented reopen triggers before resolving the case.

Fake Log Panel

Fake End-to-End SIEM Triage Timeline

training-log-viewer.log
08:58 ROLE state='active'
09:00 APPROVAL state='expired'
09:02 GROUP state='active' health='degraded'
09:04 SESSION state='active' service='critical'
09:07 IMPACT service='none-confirmed'
09:08 ALERT state='new'
09:10 CASE state='in-review'
09:13 SOURCE extension='conditional'
09:15 REQUEST identity='sent'
09:15 REQUEST source='sent'
09:15 REQUEST service='sent'
09:31 ESCALATION level='3'
09:38 ACTION role-revocation='initiated'
09:44 VALIDATION role='revoked'
09:44 VALIDATION session='closed'
09:49 SOURCE extension='recovering'
10:12 EVIDENCE extension='no-valid-match'
10:18 IMPACT service='none-confirmed'
10:25 CASE state='conditional'
18:12 CLOSURE readiness='incomplete'

Training note: this is fake data for defensive analysis practice only.

Fictional Evidence Matrix

What the Capstone Evidence Supports—and What It Does Not Prove

CAP-E01

Role and session evidence

Observation

Role and session remain Active after approval_end.

Supports

A stale-authority review is justified.

Does not prove

Does not prove harmful intent, unauthorized use, or service impact.

Capstone use

Set High priority with bounded authorization questions.

CAP-E02

Extension-source health

Observation

Extension source is Conditional and delayed.

Supports

Authorization absence cannot be confirmed at alert time.

Does not prove

Does not prove a valid extension exists.

Capstone use

Keep authorization confidence Moderate and request source-side evidence.

CAP-E03

Group-source health

Observation

Group source is Degraded and reports Active membership.

Supports

Effective-access state may remain active but confidence is limited.

Does not prove

Does not prove exact access state for the full period.

Capstone use

Assign source-health ownership and keep the case Conditional.

CAP-E04

Service evidence

Observation

Critical service remains available with no confirmed current impact.

Supports

Active service impact is not currently supported.

Does not prove

Does not remove authority, privacy, or evidence concerns.

Capstone use

Keep severity and active impact separate.

CAP-E05

Change evidence

Observation

Recovery change exists but ends earlier and covers a different destination.

Supports

The change provides partial context only.

Does not prove

Does not prove the later session was unauthorized.

Capstone use

Keep as an alternative requiring owner review.

CAP-E06

Recovered extension evidence

Observation

No valid matching extension exists for the observed period and destination.

Supports

Historical authorization confidence increases.

Does not prove

Does not prove intent or privileged modification.

Capstone use

Support the stale-authority conclusion and corrective-action review.

CAP-E07

Action validation

Observation

Role source reports Revoked and session source reports Closed.

Supports

The immediate active condition ended.

Does not prove

Does not complete group reconciliation, historical review, residual risk, or closure.

Capstone use

Move from Escalated to Conditional rather than directly to Resolved.

CAP-E08

Quality review

Observation

Replay creates duplicate raw alerts while changed destinations remain meaningful.

Supports

Narrow deduplication may reduce workload.

Does not prove

Does not justify broad grouping or suppression.

Capstone use

Test exact uniqueness plus break conditions in shadow mode.

Analyze the Evidence

What Is the Best Final Capstone Decision?

Role source reports Revoked.
Observed session source reports Closed.
Recovered extension evidence shows no valid matching extension.
Service owner and service source report no confirmed current impact.
Group source remains Recovering.
Residual-risk ownership is incomplete.
Replay-deduplication tuning has not passed every coverage test.
Reopen triggers are documented.

Which fictional decision is best supported at 10:25?

Common Mistakes

Avoid Ten Capstone Errors

Starting with the alert title

Fictional observation

A fictional analyst writes confirmed unauthorized access before reviewing source health.

Decision impact

Unsupported certainty controls the case.

Professional correction

Begin with a neutral observation and primary defender question.

Treating normalized fields as direct facts

Fictional observation

A derived expired state is documented as a source-recorded value.

Decision impact

Transformation assumptions disappear.

Professional correction

Preserve source value, normalized value, transformation, and limitation.

Using severity as priority

Fictional observation

A High-severity alert is prioritized without confidence, active effect, scope, timing, or recoverability.

Decision impact

Queue decisions become inconsistent.

Professional correction

Separate severity, confidence, and priority.

Ignoring source health

Fictional observation

No-visible extension is treated as proof of no extension during delay.

Decision impact

Missing evidence becomes false absence.

Professional correction

Use Conditional, Source-Degraded, or Unknown states.

Escalating without a question

Fictional observation

The case is sent to several teams with no bounded request.

Decision impact

Ownership and response quality weaken.

Professional correction

Assign separate identity, source, service, and leadership questions.

Closing after action

Fictional observation

The case closes immediately after role revocation begins.

Decision impact

Sessions, group state, source recovery, validation, and residual risk remain unresolved.

Professional correction

Separate action, validation, outcome, closure, and reopening.

Broad suppression

Fictional observation

All stale-role alerts are suppressed during source recovery.

Decision impact

Meaningful stale authority may disappear.

Professional correction

Repair the source and test narrow deduplication or expected handling.

Alert count as quality proof

Fictional observation

A tuning proposal passes because volume falls.

Decision impact

Changed destinations, second sessions, and false-negative risk may be hidden.

Professional correction

Require uniqueness, coverage, regression, and rollback tests.

Leadership overstatement

Fictional observation

A briefing claims an incident was prevented even though only stale authority was confirmed.

Decision impact

Risk and program performance are misrepresented.

Professional correction

Separate confirmed facts, unresolved questions, actions, outcomes, and residual risk.

Real material in the capstone

Fictional observation

A portfolio package includes sanitized real alerts, screenshots, owner messages, or timelines.

Decision impact

Sensitive systems, people, suppliers, priorities, and methods may be exposed.

Professional correction

Invent every organization, record, alert, identity, service, owner, date, decision, action, and outcome.

Safe Fictional Capstone Lab

Complete Ten Capstone Phases

Use only the supplied fictional Northbridge evidence. Do not access, copy, sanitize, upload, query, investigate, tune, suppress, deploy, escalate, close, reopen, or modify any real SIEM, alert, case, source, identity, account, endpoint, network, domain, service, supplier, organization, system, or person.
Phase 1

Mission and safety

Document the fictional mission, service, stakeholders, identity model, evidence sources, privacy boundary, and fictionalization statement.

Required output

Mission and safety charter

Quality gate

No real organization, system, identity, address, screenshot, or alert appears.

Phase 2

Sources and health

Classify identity, role, group, extension, session, service, change, and source-health evidence.

Required output

Source inventory and health matrix

Quality gate

Every conclusion shows which health conditions support or limit it.

Phase 3

Normalization and correlation

Preserve source values, document transformations, join relationships, and overlay service, change, and health context.

Required output

Normalization and correlation workbook

Quality gate

Derived context is never presented as direct evidence.

Phase 4

Alert contract

Write observation, question, evidence, health behavior, severity, confidence, priority, alternatives, non-proof statements, owners, and triggers.

Required output

Complete alert contract

Quality gate

The alert states what it supports and does not prove.

Phase 5

Triage

Build authorization, effective-access, service, impact, source-health, scope, alternative, ownership, and closure questions.

Required output

Question map and evidence requests

Quality gate

Every request is purpose-limited, owned, time-bounded, and decision-linked.

Phase 6

Severity and priority

Evaluate potential consequence, certainty, active effect, time sensitivity, scope, recoverability, ownership, and source health.

Required output

Severity-confidence-priority record

Quality gate

The three concepts remain separate.

Phase 7

Escalation and case

Assign escalation types, levels, owners, deadlines, acceptance, chronology, notes, decisions, actions, validation, and states.

Required output

Escalation and case package

Quality gate

One coordinating owner preserves the complete case.

Phase 8

Dashboards and metrics

Evaluate volume, uniqueness, source health, queue age, owner delay, case quality, coverage, workload, privacy, and residual risk.

Required output

Decision-oriented dashboard review

Quality gate

Averages, denominators, duplicates, and blind periods are addressed.

Phase 9

Quality improvement

Classify replay duplication, propose narrow deduplication, define breaks, test in shadow mode, assign rollback, and document expiration.

Required output

Tuning and rollback package

Quality gate

Lower count cannot pass when coverage tests fail.

Phase 10

Closure and communication

Review authorization, scope, impact, validation, source health, residual risk, closure, reopening, and leadership decisions.

Required output

Closure review and leadership brief

Quality gate

The case cannot close while required source or risk obligations remain incomplete.

Scenario Decision Lab

The Session Ends before Source Recovery

Fictional Northbridge validates role revocation and session closure, but extension and group sources are still Recovering. No current service impact is confirmed.

Scenario Decision Lab

Replay Tuning Hides a Changed Destination

A fictional deduplication proposal reduces raw alerts by 60%, but shadow testing shows a changed destination is grouped into the original case.

Advanced Challenge

Defend the Entire SIEM Triage Case before a Review Board

Present the fictional Northbridge case as though a review board asks why the alert existed, why priority was High, why the case escalated, why the conclusion remained Conditional, why source health mattered, why the case did not close after revocation, and why narrow deduplication is safer than broad suppression.

Defend the evidence chain

Explain raw evidence, parsing, normalization, enrichment, correlation, provenance, timing, source health, and limitations.

Defend the alert

Explain observation, defender question, required evidence, severity, confidence, priority, alternatives, and non-proof statements.

Defend triage and escalation

Explain questions, owners, deadlines, source-health limits, escalation types, levels, acceptance, aging, and de-escalation.

Defend the case

Explain chronology, notes, hypotheses, decisions, actions, validation, state changes, residual uncertainty, and reopening.

Defend the metrics

Explain volume, uniqueness, queue age, owner delay, source health, quality, coverage, workload, privacy, recovery, and residual risk.

Defend quality improvement

Explain root cause, narrow deduplication, break conditions, shadow mode, regression, rollback, expiration, ownership, and residual risk.

Challenge output

Produce a fictional mission charter, source inventory, source-health matrix, evidence ledger, normalization map, correlation model, alert contract, severity-confidence-priority record, triage question map, alternative matrix, escalation plan, chronology, case notes, dashboard review, metric dictionary, tuning proposal, validation matrix, rollback plan, closure review, residual-risk record, leadership brief, and public portfolio boundary.

Defender Habits

SIEM Triage Capstone Checklist

Check Your Understanding

A6.10 Mini Quiz: SIEM Triage Lab

Choose your answers first. Explanations appear only after submission.

1. What is the strongest first step in the fictional A6 capstone?

2. Why is fictional authorization confidence only Moderate at alert time?

3. Which fictional priority decision is strongest?

4. What should happen after role revocation and session closure are validated?

5. Which fictional noise-reduction proposal is strongest?

6. When should the fictional case be reopened?

7. Which public portfolio approach is safest?

Portfolio Prompt

Portfolio Prompt

Create a fully fictional SIEM Triage Capstone Package for the Northbridge Student-Support Cooperative. Include mission, stakeholders, critical service, identity model, source inventory, source IDs, source roles, required fields, source owners, source-health states, raw evidence IDs, event times, collection times, processing times, source records, supports, non-proof statements, parsed fields, normalized fields, enrichment, derived context, transformations, mapping risks, correlations, alert title, primary defender question, neutral observation, required evidence, severity, confidence, priority, alternatives, review triggers, triage questions, evidence requests, owners, deadlines, escalation types, escalation levels, acceptance criteria, chronology, case notes, hypotheses, decisions, actions, validation, state changes, dashboard reviews, metrics, tuning root cause, proposed change, break conditions, validation cases, shadow comparison, rollout, rollback, expiration, closure criteria, residual uncertainty, residual risk, reopen triggers, leadership brief, advanced challenge, reflection, and a statement that every organization, record, alert, identity, service, owner, date, decision, action, metric, and outcome is invented.

Keep the fictional evidence chain and decision chain traceable from source to closure.
Separate observation, authorization, impact, severity, confidence, priority, action, validation, outcome, and residual risk.
Use source-health-aware uncertainty rather than forcing missing evidence into yes-or-no conclusions.
Preserve coverage through break conditions, validation, shadow comparison, rollback, expiration, and review.
Keep the entire artifact completely fictional, defensive, non-operational, privacy-safe, evidence-aware, maintainable, and suitable for a public learning portfolio.

Confidence / Readiness Reflection

Are You Ready for the A6 Module Test?

Rate your readiness from 1 to 5 for SIEM purpose, source inventory, collection, normalization, correlation, alert rules, severity, confidence, priority, triage questions, evidence review, escalation, case notes, dashboards, metrics, noise reduction, tuning, validation, rollback, closure, reopening, and complete fictionalization.

I can explain the complete fictional path from source evidence to a case decision.
I can preserve source-health limits and evidence provenance.
I can separate severity, confidence, priority, active effect, scope, and urgency.
I can create bounded triage questions and owner requests.
I can escalate without exaggerating conclusions or abandoning case ownership.
I can maintain professional chronology, notes, decisions, actions, validation, closure, and reopening.
I can evaluate dashboards and tuning for misleading metrics, false negatives, coverage, rollback, and residual risk.
I can produce a safe fictional capstone without copying any real alert, case, source, system, or organization detail.
Record one fictional evidence fact, one source-health limitation, one priority reason, one triage question, one escalation trigger, one closure gap, one tuning break condition, and one concept to review before the module test.

Key Takeaways

What You Should Remember

1.A fictional SIEM investigation is a connected chain of source evidence, normalization, correlation, alert meaning, triage, escalation, case management, metrics, and improvement.
2.Source health changes what conclusions are supported and can prevent both confirmation and absence claims.
3.Severity, confidence, priority, active effect, scope, time sensitivity, and recoverability should remain separate.
4.A strong alert contract states what matched, what evidence exists, what the alert supports, and what it does not prove.
5.Triage should ask bounded identity, authorization, service, impact, source-health, scope, alternative, ownership, and closure questions.
6.Escalation should expand expertise, authority, coordination, or urgency without exaggerating conclusions or abandoning ownership.
7.Actions, validation, outcomes, closure, and reopening are separate lifecycle stages.
8.Dashboards and metrics should balance speed, quality, coverage, source health, workload, privacy, recovery, and residual risk.
9.Noise reduction should address root cause and preserve meaningful identity, session, destination, service, result, scope, and source-health changes.
10.Every CyberShield capstone artifact must remain fully fictional, authorized, defensive, non-operational, privacy-safe, and incapable of exposing real systems or people.

Navigation

Complete Module A6

You have completed all ten A6 lessons. Next, take the A6 Module Test covering SIEM purpose, collection, normalization, correlation, severity, priority, triage, escalation, case management, dashboards, metrics, quality improvement, and the capstone workflow.