Case
A fictional organized record that connects one or more related alerts, evidence items, actions, decisions, owners, communications, and outcomes.
Learn how defenders open, scope, own, document, link, investigate, communicate, validate, review, and close fictional SOC cases while preserving traceable evidence and clear limitations.
Lesson Progress
High School Intermediate • I15: Security Operations Basics • Lesson 3 of 8
Readiness Check
0/5 ready
Professional Hook
A fictional Northbridge case moves across shifts, service owners, telemetry teams, detection engineers, suppliers, responders, and leadership. If the record contains only a few informal notes, each new reviewer must guess what happened. A professional case allows another authorized reviewer to reconstruct the question, scope, evidence, timeline, actions, decisions, communications, limitations, validation, and closure.
Weak case record
Paste untraceable evidence, mix facts and guesses, omit timestamps, record actions without authority, communicate inconsistently, and close when the alert stops.
Professional case record
Define scope, index evidence, build a timeline, preserve uncertainty, assign ownership, document decisions, validate outcomes, and complete quality review.
Objective 1
Explain how fictional case management connects triage, ownership, scope, evidence, timeline, actions, decisions, communications, validation, closure, and improvement.
Objective 2
Distinguish fictional alerts, cases, incidents, evidence items, analyst notes, findings, hypotheses, decisions, tasks, and closure records.
Objective 3
Build a fictional SOC case file that is reconstructable, privacy-safe, evidence-limited, and suitable for shift handoff and quality review.
Objective 4
Evaluate fictional evidence using relevance, source health, timestamps, traceability, integrity concepts, scope, consistency, confidence, and limitations.
Objective 5
Create a portfolio-safe fictional case-management package with a case charter, evidence register, timeline, action log, communication record, findings, closure criteria, and leadership summary.
Why This Matters
Fictional SOC decisions may affect access, critical services, suppliers, recovery, privacy, leadership communication, and residual risk. Weak case records create duplicated work, unsupported conclusions, delayed response, poor handoffs, and unreliable metrics. Strong case management turns separate actions into one reviewable evidence-to-decision chain.
Core Concept
Scope
Which fictional question, assets, identities, services, data, suppliers, time window, environment, and exclusions define the case?
Evidence
Which fictional sources, records, owners, timestamps, health checks, handling details, confidence, and limitations support review?
Timeline
Which fictional events, alerts, actions, approvals, communications, source gaps, decisions, and validations occurred and when?
Decision
Which fictional finding, owner, authority, action, deadline, rollback, communication, and residual-risk decision follow from the evidence?
Closure
Which fictional security, business, source-health, control, supplier, communication, signoff, retention, and improvement conditions are complete?
Key Vocabulary
A fictional organized record that connects one or more related alerts, evidence items, actions, decisions, owners, communications, and outcomes.
The fictional analyst or responder accountable for maintaining case quality, status, evidence references, actions, decisions, communications, and next steps.
A fictional approved record, event, configuration, statement, test result, source-health record, or artifact used to support or challenge a conclusion.
A fictional index that records evidence identifiers, sources, owners, timestamps, relevance, health, scope, handling, confidence, and limitations.
A fictional ordered record of alerts, evidence, actions, communications, approvals, changes, decisions, and validation events.
A fictional record of tasks performed, requested, blocked, approved, completed, validated, or reassigned during a case.
A fictional record of what was decided, by whom, with which authority, based on which evidence, under which limitations, and with which review date.
A fictional evidence-supported statement that separates direct observations, interpretation, alternatives, confidence, limitations, and required action.
A fictional possible explanation that guides evidence collection but is not treated as a proven conclusion.
A fictional record of who collected, transferred, accessed, stored, or reviewed an evidence item and when.
A fictional assurance concept that an evidence item remains traceable, protected from unauthorized change, and suitable for the intended decision.
A fictional label such as New, Triaging, Investigating, Awaiting Owner, Responding, Monitoring, Ready for Review, or Closed.
A fictional relationship between alerts, cases, incidents, suppliers, changes, controls, risks, or prior records.
Fictional conditions that must be satisfied before the case is considered complete.
A fictional rule describing how long approved case records and evidence references should remain available.
A fictional peer or management check of case reasoning, evidence, ownership, timeliness, communication, validation, and closure.
Case Design
Strong case
The fictional case has a unique identifier, clear title, business service, assets, identities, data, suppliers, time window, environment, and explicit exclusions.
Weak case
The case title repeats the alert name but does not define what is actually being investigated.
Reviewer question
What exact question does the case answer?
Strong case
The fictional case owner, service owner, control owner, risk owner, supplier owner, responder, communicator, and decision authority are identified.
Weak case
The case is assigned to the SOC with no specific accountable role.
Reviewer question
Who owns the work, service, control, risk, and final decision?
Strong case
Each fictional item has an identifier, source, owner, timestamp, relevance, source health, scope, handling record, confidence, and limitation.
Weak case
The analyst pastes untraceable text or screenshots into notes.
Reviewer question
Can another reviewer locate and understand each supporting item?
Strong case
The fictional case records alert receipt, event time, evidence collection, actions, approvals, communications, source gaps, decisions, validation, and closure in order.
Weak case
Notes are written as a paragraph with no timestamps.
Reviewer question
Can another reviewer reconstruct what happened and when?
Strong case
The fictional case separates direct observations, supported conclusions, hypotheses, alternatives, missing evidence, potential impact, confirmed impact, and unsupported claims.
Weak case
Possible explanations are written as facts.
Reviewer question
Which statements are observed, inferred, possible, or unproven?
Strong case
The fictional record identifies requested and completed actions, owner, authority, reason, result, rollback, validation, and decision deadline.
Weak case
A ticket is marked complete without explaining what changed or who approved it.
Reviewer question
What was done, why, by whom, with what result?
Strong case
The fictional case records audience, sender, approved facts, uncertainty, impact status, decision needs, commitments, and next update.
Weak case
Informal messages create conflicting or unsupported statements.
Reviewer question
Who was told what, when, and under which evidence limits?
Strong case
The fictional case closes only after security and business validation, source-health review, residual risk, owner signoff, follow-up, metrics, and improvement actions.
Weak case
The case closes when the alert disappears or the shift ends.
Reviewer question
What proves the case is complete and what must improve?
Evidence Quality
Good practice
The fictional evidence directly supports or challenges the case question, scope, timeline, identity, service, control, impact, or action.
Quality risk
A large amount of technically interesting data is included even though it does not affect the decision.
Review check
Why is this item needed?
Good practice
The fictional source is current, timely, correctly parsed, available, owned, and known to cover the intended data.
Quality risk
A delayed, stale, incomplete, duplicated, or misparsed source is treated as fully reliable.
Review check
Can the source support the conclusion?
Good practice
The fictional event, receipt, collection, action, communication, and validation times are distinguished and normalized.
Quality risk
Different time zones or delayed ingestion create a false sequence.
Review check
Which time does each timestamp represent?
Good practice
The fictional item has a stable identifier, origin, owner, collection method, case link, and reviewer path.
Quality risk
Evidence is copied without a source reference.
Review check
Can another reviewer find the original approved record?
Good practice
The fictional item is protected, access-controlled, versioned, and documented during collection, transfer, review, and storage.
Quality risk
Analyst notes overwrite the original or mix observations with interpretations.
Review check
How do we know which record was reviewed?
Good practice
The fictional evidence is compared across independent or complementary sources and conflicts are documented.
Quality risk
One source is accepted even when another healthy source disagrees.
Review check
Do related sources support the same event and scope?
Good practice
The fictional item identifies included systems, identities, data, actions, time periods, regions, suppliers, and exclusions.
Quality risk
A narrow event is described as organization-wide.
Review check
What does the item cover and not cover?
Good practice
The fictional case records how strongly the evidence supports the conclusion and what remains unknown.
Quality risk
The finding sounds certain even when evidence is partial.
Review check
What could change this conclusion?
Case Status Model
Meaning
A fictional alert or request has been received but source validation and ownership are not complete.
Entry condition
Alert or request meets case-opening criteria.
Exit condition
Owner, scope, source health, and initial priority are documented.
Meaning
A fictional analyst is validating sources, gathering context, checking duplicates, and assigning priority.
Entry condition
Initial owner accepts the record.
Exit condition
Disposition is documented and the case is closed, linked, monitored, or advanced.
Meaning
The fictional case requires deeper evidence correlation, owner context, hypotheses, findings, or scope review.
Entry condition
Triage identifies unresolved questions or meaningful risk.
Exit condition
The case moves to response, owner decision, monitoring, or review.
Meaning
A fictional service, control, supplier, risk, privacy, or business owner must provide evidence or authority.
Entry condition
The request, deadline, and escalation path are documented.
Exit condition
The owner responds or escalation changes the action path.
Meaning
Authorized fictional containment, correction, recovery, source repair, access change, or supplier action is underway.
Entry condition
Action authority, plan, owner, rollback, communication, and validation are approved.
Exit condition
Action results are available for validation.
Meaning
The fictional immediate action is complete or risk is stable, but defined observation or supplier recovery continues.
Entry condition
Monitoring objective, duration, source, threshold, owner, and escalation trigger are documented.
Exit condition
The monitoring condition is satisfied or requires renewed action.
Meaning
The fictional case owner believes evidence, actions, validation, decisions, and closure criteria are complete.
Entry condition
Required records and signoffs are assembled.
Exit condition
Peer or manager approves closure or returns the case for correction.
Meaning
The fictional case has approved closure, retained evidence references, residual-risk disposition, follow-up, and review triggers.
Entry condition
Security and business outcomes are validated and owner signoff is recorded.
Exit condition
A new event or reassessment trigger may reopen or create a linked case.
Case Register
Scope
Confidential support service, maintenance identity, approved change window, related alert and storage evidence.
Evidence
Healthy primary alert source, approved change, authorized identity, two prior similar events, delayed supporting storage source.
Decision
Continue validation and detection-tuning review; incident declaration is not supported.
Next action
Recover or justify the delayed source and complete service-owner validation.
Evidence limit
No unauthorized access, exposure, or service impact is confirmed.
Scope
One limited supplier account, confidential support service, expired exception, ended project, and incomplete activity review.
Evidence
Identity register, exception record, sponsor record, project closure, service scope, and access status.
Decision
Remove or narrowly renew the access through authorized governance.
Next action
Complete post-expiration activity review and validate approved support needs.
Evidence limit
No misuse or disclosure is confirmed.
Scope
Reporting Service audit source, forty-minute gap, compensating sources, affected case coverage, and restoration.
Evidence
Source-health monitor, expected delivery, last received event, parser status, service ownership, and compensating records.
Decision
Treat as High-priority monitoring risk and restore source delivery.
Next action
Validate recovered events, gap completeness, parsing, retention, and alert function.
Evidence limit
No malicious activity during the gap is confirmed.
Scope
One storage policy, confidential collection, change identity, approved baseline, effective permissions, and change window.
Evidence
Configuration history, identity activity, change calendar, policy baseline, service map, and current permissions.
Decision
Confirm intent and coordinate authorized rollback if the change is unsupported.
Next action
Validate effective access, service function, monitoring, and owner approval.
Evidence limit
No unauthorized data access is confirmed.
Scope
One three-week-old endpoint alert linked to a validated closed case with no new activity.
Evidence
Original case, containment record, endpoint health, validation, closure, and duplicate relationship.
Decision
Link as duplicate and close proportionately.
Next action
Peer-review the linkage and confirm no new scope.
Evidence limit
A new related event would require reassessment.
Scope
Communications provider, major user-notification window, delayed delivery, alternate channel, supplier status, and business deadline.
Evidence
Supplier status, internal delivery metrics, user-notification plan, alternate channel test, and owner communications.
Decision
Use alternate communication and monitor provider recovery.
Next action
Validate delivery completion and document supplier follow-up.
Evidence limit
Operational degradation is supported; malicious cause is not.
Scope
One administrator, approved emergency network, documented exercise, privileged session, and exercise tasks.
Evidence
Exercise plan, access approval, sign-in, session actions, owner validation, and closure record.
Decision
Classify as expected exercise behavior after final validation.
Next action
Close with evidence and note detection-tuning considerations.
Evidence limit
The exercise result does not make future unusual sign-ins automatically benign.
Scope
One fictional user, password-reset issue, repeated lockouts, help-desk case, and identity health.
Evidence
Help-desk record, password-reset timeline, sign-in failures, user validation, and identity owner review.
Decision
Resolved as a supported user issue with no compromise evidence.
Next action
Monitor only if pattern or scope changes.
Evidence limit
The result applies only to this user and time period.
Case Workflow
Confirm the fictional alert relationship, case question, scope, priority, owner, service, time window, privacy boundary, and existing records.
Output: Case charter.
Index fictional sources, identifiers, owners, timestamps, relevance, health, scope, handling, confidence, and limitations.
Output: Evidence register.
Order fictional event, alert, receipt, collection, action, communication, approval, source-gap, validation, and closure times.
Output: Case timeline.
Separate fictional observations, supported conclusions, hypotheses, alternatives, missing evidence, potential impact, confirmed impact, and unsupported claims.
Output: Reasoning matrix.
Record fictional owner, authority, request, task, result, blocked condition, deadline, rollback, validation, and decision rationale.
Output: Action and decision log.
Document fictional audience, approved facts, uncertainty, service status, decision needs, commitments, supplier contacts, and next update.
Output: Communication record.
Confirm fictional security result, business function, source health, control operation, supplier action, recovery, residual risk, and owner approval.
Output: Validation record.
Complete fictional peer review, closure criteria, retention, linkage, lessons learned, detection or runbook updates, metrics, and reassessment triggers.
Output: Closure and improvement package.
Fake Dashboard
Training dashboard for fictional SOC case evidence only.
Open cases
6
Investigating, Awaiting Owner, Responding, Monitoring, and Ready for Review states are represented.
Evidence-quality issues
2
One delayed supporting source and one incomplete post-expiration activity review limit confidence.
Cases ready to close
3
Duplicate, exercise, and user-lockout cases are ready or already closed with proportional validation.
Fake SOC Alert
Source: Fake Northbridge Case Quality Console • Time: 8:18 PM
Fake Log Panel
18:20 EVENT maintenance-access='observed' 18:21 ALERT received='primary detection' 18:22 SOURCE primary='healthy' 18:24 SOURCE storage-support='delayed' 18:28 CASE opened='NBR-CASE-221' 18:32 OWNER assigned='Tier2-A' 18:40 CONTEXT change-window='approved' 18:44 IDENTITY maintenance='authorized' 18:52 HYPOTHESIS expected-maintenance='supported but unproven' 19:05 REQUEST service-owner='validation' 19:18 FINDING incident='not supported' 19:32 ACTION tuning-review='opened' 19:48 COMMUNICATION impact='unconfirmed' 20:05 SOURCE storage-support='still delayed' 20:12 STATUS ready-for-review='premature' 20:18 QUALITY return-to='Investigating'
Training note: this is fake data for defensive analysis practice only.
Findings Matrix
Evidence support
Open investigation, delayed supporting source, approved maintenance context, healthy primary evidence, and defined closure criteria.
Alternative
The available evidence may already be sufficient if the missing source cannot change the decision.
Limitation
The value of the missing source is not yet fully known.
Evidence support
Active account, expired exception, ended project, confidential service scope, named supplier owner, and incomplete activity review.
Alternative
A current support need may justify a narrow renewed access path.
Limitation
No misuse or disclosure is confirmed.
Evidence support
Confirmed forty-minute delivery gap, critical service, healthy source monitor, compensating sources, and no suspicious-event evidence.
Alternative
Later recovered events could change the case scope.
Limitation
The blind-spot period is not yet fully reconstructed.
Evidence support
Old event, validated containment, closed original case, no new activity, and direct duplicate relationship.
Alternative
New scope or activity would justify a separate or reopened case.
Limitation
The analyst must verify that no new evidence exists.
Evidence support
Supplier status, delayed delivery, major notification window, alternate channel, business-owner decision, and no malicious indicators.
Alternative
Later supplier evidence could identify a security cause.
Limitation
Supplier root cause is not yet final.
Evidence support
Case workflow, evidence requirements, business validation, source health, residual risk, owner signoff, and improvement needs.
Alternative
Low-risk duplicate cases may use simplified closure under an approved runbook.
Limitation
Closure depth should remain proportionate to case risk.
Analyze the Evidence
Common Mistakes
Safe Practice Lab
Your fictional assignment
Use only the supplied fictional Northbridge records to produce a complete, reviewable SOC case package.
Required deliverables
Scenario Decision Lab
The fictional maintenance explanation is well supported, but one source remains delayed and the case’s tuning action is still open.
Scenario Decision Lab
The fictional alert matches the same historical event and adds no new identity, asset, time period, activity, or impact.
Defender Habits
Check Your Understanding
Choose your answers first. Explanations appear only after submission.
Portfolio Prompt
Create a fictional Case Management and Evidence Handling Package for Northbridge. Include the case charter, case register, evidence register, normalized timeline, facts and hypothesis matrix, action log, decision log, communication record, case-linkage model, status workflow, handoff, validation, closure criteria, retention, quality review, metrics, leadership summary, reflection, and a portfolio-safety statement.
Key Takeaways
Navigation