High School IntermediateModule I16Lesson 1 of 8

I16.1 Fake Log Investigation Lab

Investigate fictional authentication, endpoint, network, application, cloud, supplier, and source-health records while preserving timeline accuracy, evidence quality, alternate explanations, confidence, ownership, and safe defensive scope.

Lesson Progress

Fake Log Investigation Lab

High School IntermediateI16: Intermediate Defensive Labs • Lesson 1 of 8

13% complete

Readiness Check

Before You Start

0/5 ready

Professional Hook

The Same Logs Can Tell Different Stories if the Timeline Is Wrong

A fictional application event occurred at 19:08 but did not arrive in the monitoring system until 19:38. If the analyst treats collection time as event time, the action appears to happen after the alert instead of during approved maintenance. Professional log investigation validates source health, normalizes timestamps, and keeps observations separate from interpretation.

Weak investigation

Copy raw lines, ignore source health, mix time fields, assume missing evidence proves harm, combine unrelated events, and close when the alert disappears.

Professional investigation

Define scope, inventory sources, normalize time, correlate context, write evidence-limited findings, assign owners, validate outcomes, and improve the process.

Objective 1

Define a fictional log-investigation scope that identifies the exact question, systems, identities, services, time window, approved evidence, owners, privacy limits, and expected decisions.

Objective 2

Evaluate fictional authentication, endpoint, network, application, cloud, and source-health records for relevance, timestamp quality, completeness, duplication, conflicts, and blind spots.

Objective 3

Build a normalized fictional timeline that separates event time, collection time, alert time, analyst action time, owner response time, and validation time.

Objective 4

Write evidence-limited fictional findings that distinguish direct observations, supported conclusions, alternate explanations, missing evidence, potential impact, confirmed impact, confidence, and next action.

Objective 5

Create a portfolio-safe fictional log-investigation package with an evidence register, timeline, findings, owner map, escalation plan, validation record, leadership summary, and improvement recommendations.

Why This Matters

Logs Support Decisions Only When Their Quality and Scope Are Understood

Fictional logs may support access removal, source restoration, detection tuning, case closure, owner escalation, control rollback, supplier review, or leadership communication. A detailed record is not automatically complete or correct. Strong investigation explains which source supports which conclusion, what the source cannot prove, and what action remains necessary.

Core Concept

Use the Scope–Source–Time–Correlation–Decision Model

Scope

Which fictional question, system, identity, service, supplier, time window, exclusions, owner, and decision define the investigation?

Source

Which fictional records exist, who owns them, how healthy are they, what do they cover, and what are their limits?

Time

Which fictional event, collection, alert, action, communication, and validation times must be normalized?

Correlation

Which fictional identities, assets, services, changes, network paths, applications, cloud resources, and source-health records relate?

Decision

Which fictional conclusion, confidence, impact status, owner, action, authority, deadline, validation, and closure follow from the evidence?

Key Vocabulary

Log Investigation and Evidence Terms

Log source

A fictional system, service, application, identity platform, network device, endpoint tool, cloud platform, supplier, or monitoring component that produces approved records.

Event time

The fictional time when an action or condition occurred at the source.

Collection time

The fictional time when a monitoring pipeline received or stored the event.

Alert time

The fictional time when detection logic created a signal from one or more events.

Normalization

A fictional process that converts different event formats, fields, and time zones into a consistent investigative view.

Source health

A fictional assessment of delivery, timeliness, parsing, completeness, coverage, duplication, ownership, and known blind spots.

Evidence gap

A fictional missing, delayed, stale, incomplete, conflicting, or unavailable source that limits confidence.

Correlation

A fictional process of comparing records across sources to identify relationships in time, identity, asset, service, action, or outcome.

Direct observation

A fictional statement copied from healthy evidence without added interpretation.

Supported conclusion

A fictional interpretation that follows reasonably from multiple evidence items and clearly states confidence and limits.

Alternate explanation

A fictional plausible interpretation that also fits part of the evidence and should be tested rather than ignored.

Potential impact

A fictional harm that could result if a condition is real but has not yet been confirmed.

Confirmed impact

A fictional harm directly supported by approved evidence.

False sequence

A fictional incorrect timeline caused by delayed ingestion, time-zone mismatch, duplicated events, or misordered records.

Evidence register

A fictional index of evidence identifiers, sources, owners, timestamps, relevance, health, scope, confidence, handling, and limitations.

Validation record

A fictional record showing whether security outcome, service function, source recovery, control state, owner signoff, and residual risk were confirmed.

Evidence Register

Twelve Fictional Northbridge Log Sources

NBR-LOG-01

Fictional identity sign-in service

HealthyIdentity Owner

Record

A supplier account signed in to the confidential support service at 18:42.

Event time

18:42:11

Collection time

18:42:20

Relevance

Directly supports current access by an identity whose approval status requires review.

Limitation

The sign-in record alone does not prove which actions followed.

NBR-LOG-02

Fictional supplier exception register

HealthyThird-Party Risk Owner

Record

The supplier access exception expired at 17:00 and no approved extension is present.

Event time

17:00:00

Collection time

17:01:05

Relevance

Supports that the current access capability is outside the documented approval window.

Limitation

A legitimate but undocumented emergency support need may exist.

NBR-LOG-03

Fictional support-service activity log

HealthyService Owner

Record

The supplier identity viewed one service-status page and attempted no configuration changes.

Event time

18:43:02

Collection time

18:43:11

Relevance

Provides limited context about post-sign-in activity.

Limitation

The source covers only the support service and not other connected systems.

NBR-LOG-04

Fictional endpoint monitoring source

HealthyEndpoint Owner

Record

The administrator workstation started an approved maintenance tool at 19:05.

Event time

19:05:44

Collection time

19:06:01

Relevance

Supports the approved maintenance explanation for one later alert.

Limitation

It does not prove every subsequent action remained within scope.

NBR-LOG-05

Fictional maintenance change record

HealthyService Owner

Record

Maintenance was approved from 19:00 to 20:00 for the reporting service and one named identity.

Event time

19:00:00

Collection time

18:00:00

Relevance

Defines the approved maintenance identity, service, task, and time boundary.

Limitation

A valid change record does not automatically make all observed activity expected.

NBR-LOG-06

Fictional network gateway

HealthyNetwork Owner

Record

The maintenance workstation connected to the reporting service at 19:07 and 19:14.

Event time

19:07:13 / 19:14:28

Collection time

19:07:17 / 19:14:34

Relevance

Corroborates the approved identity and service relationship.

Limitation

Network connection records do not show the exact application actions.

NBR-LOG-07

Fictional application audit source

DelayedApplication Owner

Record

The reporting service recorded one configuration read and one approved restart.

Event time

19:08:02 / 19:15:03

Collection time

19:38:12 / 19:38:16

Relevance

Supports expected maintenance actions but arrived thirty minutes late.

Limitation

The delay could create a false timeline if collection time is confused with event time.

NBR-LOG-08

Fictional source-health monitor

HealthyTelemetry Owner

Record

The application audit source had a thirty-one-minute delivery delay.

Event time

19:06:00

Collection time

19:06:04

Relevance

Explains why supporting application records appeared after the alert.

Limitation

The monitor proves delay, not the completeness of all recovered events.

NBR-LOG-09

Fictional cloud storage configuration history

HealthyCloud Control Owner

Record

A confidential storage policy changed at 20:11 outside the approved change window.

Event time

20:11:26

Collection time

20:11:31

Relevance

Supports an unsupported configuration change requiring owner review.

Limitation

The record does not confirm whether effective access expanded.

NBR-LOG-10

Fictional storage access monitor

Healthy with limited scopeCloud Security Owner

Record

No new external access event was observed between 20:11 and 20:45.

Event time

20:11–20:45

Collection time

20:46:02

Relevance

Provides some evidence against immediate confirmed data access.

Limitation

The source may not cover every access path or delayed event.

NBR-LOG-11

Fictional reporting audit-source monitor

HealthyTelemetry Owner

Record

A critical audit source stopped delivering events at 21:02.

Event time

21:02:00

Collection time

21:02:05

Relevance

Supports a current monitoring blind spot on a critical service.

Limitation

The source gap does not prove malicious activity occurred.

NBR-LOG-12

Fictional compensating service record

HealthyService Owner

Record

Alternate service-health and change records remained current during the source gap.

Event time

21:02–21:37

Collection time

Current

Relevance

Provides partial compensating evidence while the preferred source is unavailable.

Limitation

Coverage is narrower than the missing audit source.

Normalized Timeline

Fourteen Fictional Events in Investigative Order

1

17:00

Governance

Fictional supplier access exception expires.

NBR-LOG-02

Documented approval ends.

2

18:42

Identity

Supplier account signs in to the confidential support service.

NBR-LOG-01

Current access occurs after expiration.

3

18:43

Service

Supplier identity views one status page.

NBR-LOG-03

Limited activity is observed; broader misuse is not supported.

4

19:00

Change

Approved maintenance window begins.

NBR-LOG-05

Maintenance context becomes active.

5

19:05

Endpoint

Approved maintenance tool starts.

NBR-LOG-04

Expected maintenance behavior is supported.

6

19:07

Network

Maintenance workstation connects to the reporting service.

NBR-LOG-06

Identity and service relationship is corroborated.

7

19:08

Application

Configuration read occurs.

NBR-LOG-07

Action fits the approved task but arrives late.

8

19:15

Application

Approved restart occurs.

NBR-LOG-07

Expected action is supported.

9

19:38

Collection

Delayed application records arrive.

NBR-LOG-07 / NBR-LOG-08

Collection delay explains the initial evidence gap.

10

20:11

Cloud

Confidential storage policy changes outside the approved window.

NBR-LOG-09

Unsupported control change requires review.

11

20:46

Validation

No covered external access is observed after the storage change.

NBR-LOG-10

Confirmed access impact remains unsupported.

12

21:02

Telemetry

Critical reporting audit source stops delivering.

NBR-LOG-11

Current monitoring blind spot begins.

13

21:10

Operations

Compensating service records are confirmed healthy.

NBR-LOG-12

Partial visibility remains available.

14

21:37

Telemetry

Preferred source restoration is still pending.

NBR-LOG-11

High-priority source-health work remains open.

Investigation Workflow

Eight Steps from Scope to Improvement

1

Define the investigation question

State the fictional event, identity, system, service, time window, business context, approved evidence, exclusions, owners, and required decision.

Output: Investigation charter.

2

Inventory and validate sources

List fictional sources, owners, timestamps, health, coverage, parsing, duplicates, delays, conflicts, relevance, and limitations.

Output: Evidence register.

3

Normalize the timeline

Separate fictional event time, collection time, alert time, action time, communication time, and validation time.

Output: Normalized timeline.

4

Correlate identities, assets, and services

Compare fictional users, service accounts, suppliers, endpoints, network records, applications, cloud resources, changes, and owners.

Output: Correlation map.

5

Write findings and alternatives

Document fictional observations, supported conclusions, alternate explanations, missing evidence, confidence, potential impact, confirmed impact, and limits.

Output: Findings matrix.

6

Assign owners and actions

Route fictional identity, service, telemetry, cloud, supplier, detection, risk, communication, or response tasks with authority and deadlines.

Output: Action and escalation plan.

7

Validate outcomes

Confirm fictional access state, source recovery, effective permissions, service function, detection behavior, owner decisions, and residual risk.

Output: Validation record.

8

Close and improve

Complete fictional peer review, closure criteria, retention, handoff, metrics, source, detection, runbook, training, and governance improvements.

Output: Closure and improvement package.

Fake Dashboard

Fake Northbridge Log Investigation Dashboard

Training dashboard for fictional evidence only.

Sources reviewed

12

Identity, governance, service, endpoint, network, application, cloud, telemetry, and compensating records are represented.

Open evidence gaps

2

One delayed application source and one active critical audit-source gap limit current assurance.

Confirmed incidents

0

The fictional evidence supports active risks and control actions but no confirmed incident.

Fake SOC Alert

Expired Supplier Access and Critical Audit Gap Require Separate Cases

Source: Fake Northbridge Investigation Console • Time: 9:42 PM

High Severity
A fictional supplier identity accessed a confidential service after approval expiration while a separate critical audit source remains unavailable. The records involve different systems, owners, evidence, and decisions.
Defensive recommendation: Open separate cases, remove or narrowly renew supplier access, restore or fail over the source, preserve evidence limits, assign owners and deadlines, validate outcomes, and avoid combining the records into one unsupported incident.

Fake Log Panel

Fake Northbridge Mixed Log Extract

training-log-viewer.log
17:00:00 EXCEPTION supplier-support='expired'
18:42:11 AUTH supplier-identity='success'
18:43:02 SERVICE page='status-view'
19:00:00 CHANGE maintenance-window='open'
19:05:44 ENDPOINT tool='approved-maintenance'
19:07:13 NETWORK destination='reporting-service'
19:08:02 APP action='configuration-read'
19:15:03 APP action='approved-restart'
19:38:12 COLLECTION app-source='delayed'
20:11:26 CLOUD policy-change='outside-window'
20:46:02 ACCESS external-events='none-observed-in-covered-source'
21:02:00 SOURCE reporting-audit='delivery-stopped'
21:10:00 COMPENSATE service-records='healthy'
21:37:00 SOURCE restoration='pending'

Training note: this is fake data for defensive analysis practice only.

Findings Matrix

Six Fictional Findings with Confidence and Limits

NBR-FIND-01High

The fictional supplier account used active access after its documented exception expired.

Evidence support

Healthy identity sign-in, healthy exception record, confidential service scope, and post-sign-in service activity.

Alternate explanation

A legitimate but undocumented emergency support need may exist.

Impact statement

Unsupported capability is confirmed; misuse and disclosure are not confirmed.

Next action

Identity, service, and third-party risk owners should remove or narrowly renew access and complete activity review.

NBR-FIND-02High

The fictional maintenance activity is strongly supported as expected behavior within the approved scope.

Evidence support

Approved change, approved identity, approved tool, network connection, delayed application records, and source-health explanation.

Alternate explanation

An unobserved out-of-scope action may still exist because one source was delayed.

Impact statement

No unauthorized action or service impact is confirmed.

Next action

Complete source recovery review and open a narrow detection-tuning task.

NBR-FIND-03High

The fictional application source delay created a misleading evidence sequence during maintenance triage.

Evidence support

Event times at 19:08 and 19:15, collection times near 19:38, and healthy source-health evidence confirming delay.

Alternate explanation

Some individual application events may also be missing.

Impact statement

Investigation confidence was reduced temporarily; malicious activity is not supported.

Next action

Improve source-delay monitoring, analyst timeline guidance, and closure criteria.

NBR-FIND-04Medium-High

The fictional storage-policy change requires owner review and rollback preparation.

Evidence support

Healthy configuration history, confidential scope, no matching approved window, and limited post-change access evidence.

Alternate explanation

The change may be legitimate but undocumented.

Impact statement

Possible access-control exposure exists; unauthorized data access is unconfirmed.

Next action

Validate effective permissions and authorize rollback if unsupported.

NBR-FIND-05High

The fictional critical audit-source gap is a High-priority monitoring risk.

Evidence support

Healthy source-health monitor, critical service, current thirty-five-minute gap, and narrower compensating evidence.

Alternate explanation

The outage may be a nonsecurity operational failure.

Impact statement

Monitoring assurance is reduced; malicious activity during the gap is not confirmed.

Next action

Restore or fail over the source, preserve the gap window, and validate recovered events.

NBR-FIND-06High

The supplied fictional records support multiple separate cases rather than one combined incident.

Evidence support

Different identities, services, time periods, owners, evidence sources, causes, decisions, and confidence levels.

Alternate explanation

Later evidence could identify a relationship between some records.

Impact statement

Combining them now would create unsupported scope and confusing ownership.

Next action

Maintain separate case records with explicit links only where evidence supports a relationship.

Analyze the Evidence

Did the Delayed Application Log Prove the Maintenance Alert Was Malicious?

The fictional maintenance window was approved from 19:00 to 20:00.
The approved maintenance identity and tool were used.
Network records show connections to the approved reporting service.
Application actions occurred at 19:08 and 19:15.
The application records were collected near 19:38 because the source was delayed.
No unauthorized action or service impact is confirmed.

Which conclusion is strongest?

Common Mistakes

Mistakes That Weaken Fictional Log Investigations

Reading fictional collection time as though it were event time.
Using one source as proof when additional healthy sources disagree or remain missing.
Assuming a healthy source has complete coverage of every relevant event.
Treating missing evidence as proof that harmful activity did or did not occur.
Combining unrelated identities, services, suppliers, time periods, and owners into one case.
Copying raw log text without explaining relevance, source health, scope, confidence, and limitations.
Writing alternate explanations as confirmed facts.
Reporting potential impact as confirmed impact.
Treating approved maintenance as proof that every action was expected.
Treating expired access as proof of malicious intent.
Closing a case when the alert stops instead of when evidence and validation criteria are complete.
Ignoring source-health records when analyzing gaps, delays, or missing fields.
Taking action without the correct identity, service, cloud, supplier, risk, or response authority.
Using or exposing any real credentials, employee data, school records, company logs, supplier records, private cases, incident evidence, or confidential SOC information.

Safe Practice Lab

Build the Northbridge Fake Log Investigation Package

Your fictional assignment

Scope, Evidence, Timeline, Findings, Actions, and Validation

Use only the supplied fictional Northbridge records to create a complete, evidence-limited investigation package.

Required deliverables

  1. Investigation charter with question, scope, exclusions, owners, privacy, authority, and decision deadline.
  2. Evidence register with source, owner, event time, collection time, health, relevance, confidence, and limitations.
  3. Normalized timeline that separates event, collection, alert, action, communication, and validation times.
  4. Correlation map for identities, endpoints, network paths, services, cloud resources, changes, suppliers, and owners.
  5. Findings matrix with observations, supported conclusions, alternatives, missing evidence, confidence, potential impact, and confirmed impact.
  6. Action, escalation, communication, rollback, and validation plan.
  7. Case-boundary and evidence-linkage explanation.
  8. Technical summary, leadership summary, reflection, and portfolio-safety statement.
Complete the lab only with fictional evidence displayed on this page. Do not use real credentials, employee information, school records, company logs, supplier records, private cases, incidents, or confidential SOC information.

Scenario Decision Lab

The Analyst Wants to Merge the Supplier Access and Source Gap into One Incident

The fictional records occur during the same shift but involve different systems, owners, evidence sources, timelines, and decisions.

Scenario Decision Lab

Leadership Wants a One-Sentence Storage-Policy Update

The fictional policy changed outside the approved window, but effective permissions and data-access impact remain under review.

Defender Habits

Fake Log Investigation Checklist

Check Your Understanding

I16.1 Mini Quiz: Fake Log Investigation Lab

Choose your answers first. Explanations appear only after submission.

1. Why must event time and collection time be separated in a fictional log investigation?

2. What does the fictional expired supplier exception prove?

3. What is the strongest conclusion about the fictional maintenance activity?

4. What should happen after a fictional confidential storage policy changes outside the approved window?

5. What does a fictional critical audit-source gap prove?

6. What makes a fictional finding defensible?

7. Why should the supplied fictional records remain in separate cases?

Portfolio Prompt

Portfolio Prompt

Create a fictional Fake Log Investigation Package for Northbridge. Include the investigation charter, source inventory, evidence register, normalized timeline, correlation map, facts and alternatives matrix, findings, case-boundary decision, owner and escalation map, action plan, communication record, validation, closure criteria, improvements, leadership summary, technical summary, reflection, and a portfolio-safety statement.

Use only fictional logs, identities, systems, services, suppliers, cases, sources, timestamps, actions, decisions, and outcomes.
Do not treat source detail, alert severity, missing evidence, expired approval, approved maintenance, or absent access events as automatic proof.
Make every conclusion traceable to exact evidence, source health, scope, timeline, alternatives, confidence, limits, owner, action, and validation.
Show how collection delay can create a false sequence if timestamps are not normalized.

Key Takeaways

What You Should Remember

1.Log investigation begins with a clear question and scope.
2.Event time and collection time must be separated.
3.Source health determines how much confidence a log can support.
4.Missing evidence changes confidence but does not prove harm or safety.
5.Case boundaries should follow evidence, systems, identities, owners, timelines, and decisions.
6.Findings should distinguish observations, conclusions, alternatives, impact status, confidence, and limits.
7.Portfolio artifacts should use fully fictional evidence and never expose real organizational logs.

Navigation

Continue Module I16