Log source
A fictional system, service, application, identity platform, network device, endpoint tool, cloud platform, supplier, or monitoring component that produces approved records.
Investigate fictional authentication, endpoint, network, application, cloud, supplier, and source-health records while preserving timeline accuracy, evidence quality, alternate explanations, confidence, ownership, and safe defensive scope.
Lesson Progress
High School Intermediate • I16: Intermediate Defensive Labs • Lesson 1 of 8
Readiness Check
0/5 ready
Professional Hook
A fictional application event occurred at 19:08 but did not arrive in the monitoring system until 19:38. If the analyst treats collection time as event time, the action appears to happen after the alert instead of during approved maintenance. Professional log investigation validates source health, normalizes timestamps, and keeps observations separate from interpretation.
Weak investigation
Copy raw lines, ignore source health, mix time fields, assume missing evidence proves harm, combine unrelated events, and close when the alert disappears.
Professional investigation
Define scope, inventory sources, normalize time, correlate context, write evidence-limited findings, assign owners, validate outcomes, and improve the process.
Objective 1
Define a fictional log-investigation scope that identifies the exact question, systems, identities, services, time window, approved evidence, owners, privacy limits, and expected decisions.
Objective 2
Evaluate fictional authentication, endpoint, network, application, cloud, and source-health records for relevance, timestamp quality, completeness, duplication, conflicts, and blind spots.
Objective 3
Build a normalized fictional timeline that separates event time, collection time, alert time, analyst action time, owner response time, and validation time.
Objective 4
Write evidence-limited fictional findings that distinguish direct observations, supported conclusions, alternate explanations, missing evidence, potential impact, confirmed impact, confidence, and next action.
Objective 5
Create a portfolio-safe fictional log-investigation package with an evidence register, timeline, findings, owner map, escalation plan, validation record, leadership summary, and improvement recommendations.
Why This Matters
Fictional logs may support access removal, source restoration, detection tuning, case closure, owner escalation, control rollback, supplier review, or leadership communication. A detailed record is not automatically complete or correct. Strong investigation explains which source supports which conclusion, what the source cannot prove, and what action remains necessary.
Core Concept
Scope
Which fictional question, system, identity, service, supplier, time window, exclusions, owner, and decision define the investigation?
Source
Which fictional records exist, who owns them, how healthy are they, what do they cover, and what are their limits?
Time
Which fictional event, collection, alert, action, communication, and validation times must be normalized?
Correlation
Which fictional identities, assets, services, changes, network paths, applications, cloud resources, and source-health records relate?
Decision
Which fictional conclusion, confidence, impact status, owner, action, authority, deadline, validation, and closure follow from the evidence?
Key Vocabulary
A fictional system, service, application, identity platform, network device, endpoint tool, cloud platform, supplier, or monitoring component that produces approved records.
The fictional time when an action or condition occurred at the source.
The fictional time when a monitoring pipeline received or stored the event.
The fictional time when detection logic created a signal from one or more events.
A fictional process that converts different event formats, fields, and time zones into a consistent investigative view.
A fictional assessment of delivery, timeliness, parsing, completeness, coverage, duplication, ownership, and known blind spots.
A fictional missing, delayed, stale, incomplete, conflicting, or unavailable source that limits confidence.
A fictional process of comparing records across sources to identify relationships in time, identity, asset, service, action, or outcome.
A fictional statement copied from healthy evidence without added interpretation.
A fictional interpretation that follows reasonably from multiple evidence items and clearly states confidence and limits.
A fictional plausible interpretation that also fits part of the evidence and should be tested rather than ignored.
A fictional harm that could result if a condition is real but has not yet been confirmed.
A fictional harm directly supported by approved evidence.
A fictional incorrect timeline caused by delayed ingestion, time-zone mismatch, duplicated events, or misordered records.
A fictional index of evidence identifiers, sources, owners, timestamps, relevance, health, scope, confidence, handling, and limitations.
A fictional record showing whether security outcome, service function, source recovery, control state, owner signoff, and residual risk were confirmed.
Evidence Register
Record
A supplier account signed in to the confidential support service at 18:42.
Event time
18:42:11
Collection time
18:42:20
Relevance
Directly supports current access by an identity whose approval status requires review.
Limitation
The sign-in record alone does not prove which actions followed.
Record
The supplier access exception expired at 17:00 and no approved extension is present.
Event time
17:00:00
Collection time
17:01:05
Relevance
Supports that the current access capability is outside the documented approval window.
Limitation
A legitimate but undocumented emergency support need may exist.
Record
The supplier identity viewed one service-status page and attempted no configuration changes.
Event time
18:43:02
Collection time
18:43:11
Relevance
Provides limited context about post-sign-in activity.
Limitation
The source covers only the support service and not other connected systems.
Record
The administrator workstation started an approved maintenance tool at 19:05.
Event time
19:05:44
Collection time
19:06:01
Relevance
Supports the approved maintenance explanation for one later alert.
Limitation
It does not prove every subsequent action remained within scope.
Record
Maintenance was approved from 19:00 to 20:00 for the reporting service and one named identity.
Event time
19:00:00
Collection time
18:00:00
Relevance
Defines the approved maintenance identity, service, task, and time boundary.
Limitation
A valid change record does not automatically make all observed activity expected.
Record
The maintenance workstation connected to the reporting service at 19:07 and 19:14.
Event time
19:07:13 / 19:14:28
Collection time
19:07:17 / 19:14:34
Relevance
Corroborates the approved identity and service relationship.
Limitation
Network connection records do not show the exact application actions.
Record
The reporting service recorded one configuration read and one approved restart.
Event time
19:08:02 / 19:15:03
Collection time
19:38:12 / 19:38:16
Relevance
Supports expected maintenance actions but arrived thirty minutes late.
Limitation
The delay could create a false timeline if collection time is confused with event time.
Record
The application audit source had a thirty-one-minute delivery delay.
Event time
19:06:00
Collection time
19:06:04
Relevance
Explains why supporting application records appeared after the alert.
Limitation
The monitor proves delay, not the completeness of all recovered events.
Record
A confidential storage policy changed at 20:11 outside the approved change window.
Event time
20:11:26
Collection time
20:11:31
Relevance
Supports an unsupported configuration change requiring owner review.
Limitation
The record does not confirm whether effective access expanded.
Record
No new external access event was observed between 20:11 and 20:45.
Event time
20:11–20:45
Collection time
20:46:02
Relevance
Provides some evidence against immediate confirmed data access.
Limitation
The source may not cover every access path or delayed event.
Record
A critical audit source stopped delivering events at 21:02.
Event time
21:02:00
Collection time
21:02:05
Relevance
Supports a current monitoring blind spot on a critical service.
Limitation
The source gap does not prove malicious activity occurred.
Record
Alternate service-health and change records remained current during the source gap.
Event time
21:02–21:37
Collection time
Current
Relevance
Provides partial compensating evidence while the preferred source is unavailable.
Limitation
Coverage is narrower than the missing audit source.
Normalized Timeline
17:00
Governance
Fictional supplier access exception expires.
NBR-LOG-02
Documented approval ends.
18:42
Identity
Supplier account signs in to the confidential support service.
NBR-LOG-01
Current access occurs after expiration.
18:43
Service
Supplier identity views one status page.
NBR-LOG-03
Limited activity is observed; broader misuse is not supported.
19:00
Change
Approved maintenance window begins.
NBR-LOG-05
Maintenance context becomes active.
19:05
Endpoint
Approved maintenance tool starts.
NBR-LOG-04
Expected maintenance behavior is supported.
19:07
Network
Maintenance workstation connects to the reporting service.
NBR-LOG-06
Identity and service relationship is corroborated.
19:08
Application
Configuration read occurs.
NBR-LOG-07
Action fits the approved task but arrives late.
19:15
Application
Approved restart occurs.
NBR-LOG-07
Expected action is supported.
19:38
Collection
Delayed application records arrive.
NBR-LOG-07 / NBR-LOG-08
Collection delay explains the initial evidence gap.
20:11
Cloud
Confidential storage policy changes outside the approved window.
NBR-LOG-09
Unsupported control change requires review.
20:46
Validation
No covered external access is observed after the storage change.
NBR-LOG-10
Confirmed access impact remains unsupported.
21:02
Telemetry
Critical reporting audit source stops delivering.
NBR-LOG-11
Current monitoring blind spot begins.
21:10
Operations
Compensating service records are confirmed healthy.
NBR-LOG-12
Partial visibility remains available.
21:37
Telemetry
Preferred source restoration is still pending.
NBR-LOG-11
High-priority source-health work remains open.
Investigation Workflow
State the fictional event, identity, system, service, time window, business context, approved evidence, exclusions, owners, and required decision.
Output: Investigation charter.
List fictional sources, owners, timestamps, health, coverage, parsing, duplicates, delays, conflicts, relevance, and limitations.
Output: Evidence register.
Separate fictional event time, collection time, alert time, action time, communication time, and validation time.
Output: Normalized timeline.
Compare fictional users, service accounts, suppliers, endpoints, network records, applications, cloud resources, changes, and owners.
Output: Correlation map.
Document fictional observations, supported conclusions, alternate explanations, missing evidence, confidence, potential impact, confirmed impact, and limits.
Output: Findings matrix.
Route fictional identity, service, telemetry, cloud, supplier, detection, risk, communication, or response tasks with authority and deadlines.
Output: Action and escalation plan.
Confirm fictional access state, source recovery, effective permissions, service function, detection behavior, owner decisions, and residual risk.
Output: Validation record.
Complete fictional peer review, closure criteria, retention, handoff, metrics, source, detection, runbook, training, and governance improvements.
Output: Closure and improvement package.
Fake Dashboard
Training dashboard for fictional evidence only.
Sources reviewed
12
Identity, governance, service, endpoint, network, application, cloud, telemetry, and compensating records are represented.
Open evidence gaps
2
One delayed application source and one active critical audit-source gap limit current assurance.
Confirmed incidents
0
The fictional evidence supports active risks and control actions but no confirmed incident.
Fake SOC Alert
Source: Fake Northbridge Investigation Console • Time: 9:42 PM
Fake Log Panel
17:00:00 EXCEPTION supplier-support='expired' 18:42:11 AUTH supplier-identity='success' 18:43:02 SERVICE page='status-view' 19:00:00 CHANGE maintenance-window='open' 19:05:44 ENDPOINT tool='approved-maintenance' 19:07:13 NETWORK destination='reporting-service' 19:08:02 APP action='configuration-read' 19:15:03 APP action='approved-restart' 19:38:12 COLLECTION app-source='delayed' 20:11:26 CLOUD policy-change='outside-window' 20:46:02 ACCESS external-events='none-observed-in-covered-source' 21:02:00 SOURCE reporting-audit='delivery-stopped' 21:10:00 COMPENSATE service-records='healthy' 21:37:00 SOURCE restoration='pending'
Training note: this is fake data for defensive analysis practice only.
Findings Matrix
Evidence support
Healthy identity sign-in, healthy exception record, confidential service scope, and post-sign-in service activity.
Alternate explanation
A legitimate but undocumented emergency support need may exist.
Impact statement
Unsupported capability is confirmed; misuse and disclosure are not confirmed.
Next action
Identity, service, and third-party risk owners should remove or narrowly renew access and complete activity review.
Evidence support
Approved change, approved identity, approved tool, network connection, delayed application records, and source-health explanation.
Alternate explanation
An unobserved out-of-scope action may still exist because one source was delayed.
Impact statement
No unauthorized action or service impact is confirmed.
Next action
Complete source recovery review and open a narrow detection-tuning task.
Evidence support
Event times at 19:08 and 19:15, collection times near 19:38, and healthy source-health evidence confirming delay.
Alternate explanation
Some individual application events may also be missing.
Impact statement
Investigation confidence was reduced temporarily; malicious activity is not supported.
Next action
Improve source-delay monitoring, analyst timeline guidance, and closure criteria.
Evidence support
Healthy configuration history, confidential scope, no matching approved window, and limited post-change access evidence.
Alternate explanation
The change may be legitimate but undocumented.
Impact statement
Possible access-control exposure exists; unauthorized data access is unconfirmed.
Next action
Validate effective permissions and authorize rollback if unsupported.
Evidence support
Healthy source-health monitor, critical service, current thirty-five-minute gap, and narrower compensating evidence.
Alternate explanation
The outage may be a nonsecurity operational failure.
Impact statement
Monitoring assurance is reduced; malicious activity during the gap is not confirmed.
Next action
Restore or fail over the source, preserve the gap window, and validate recovered events.
Evidence support
Different identities, services, time periods, owners, evidence sources, causes, decisions, and confidence levels.
Alternate explanation
Later evidence could identify a relationship between some records.
Impact statement
Combining them now would create unsupported scope and confusing ownership.
Next action
Maintain separate case records with explicit links only where evidence supports a relationship.
Analyze the Evidence
Common Mistakes
Safe Practice Lab
Your fictional assignment
Use only the supplied fictional Northbridge records to create a complete, evidence-limited investigation package.
Required deliverables
Scenario Decision Lab
The fictional records occur during the same shift but involve different systems, owners, evidence sources, timelines, and decisions.
Scenario Decision Lab
The fictional policy changed outside the approved window, but effective permissions and data-access impact remain under review.
Defender Habits
Check Your Understanding
Choose your answers first. Explanations appear only after submission.
Portfolio Prompt
Create a fictional Fake Log Investigation Package for Northbridge. Include the investigation charter, source inventory, evidence register, normalized timeline, correlation map, facts and alternatives matrix, findings, case-boundary decision, owner and escalation map, action plan, communication record, validation, closure criteria, improvements, leadership summary, technical summary, reflection, and a portfolio-safety statement.
Key Takeaways
Navigation