Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

What exactly have I been given?

Before interpreting technical-looking material, work out what the thing actually is.

A raw log, a security alert, an incident ticket, a screenshot and an analyst summary may all describe the same incident, but they are not the same kind of evidence.

That distinction matters because each one tells you something different.

Start by classifying the item

A useful first pass is:

Material What it usually represents
Source record A system-generated record of an event
Security alert A rule, model or detection applied to one or more records
Incident ticket A developing organisational account of reports, decisions and actions
Screenshot / PDF A representation of something viewed or exported
Analyst summary A person's interpretation of underlying material
Intelligence report A wider assessment built from several sources

The closer you are to the source event, the easier it is to see what the system actually recorded.

Ask how it was produced

Suppose you are handed this:

Example supplied material
File: incident-summary.pdfCreated by: Security Operations CentrePeriod covered: 04:45–07:10 UTCContains: alert screenshots, analyst notes, selected log excerptsSource logs: not included

That may be very useful for orientation.

But if a major conclusion depends on one event in the PDF, you may need the underlying record rather than relying on the summary of it.

Record the context around the material

Useful things to capture include:

  • who created or exported it;
  • when;
  • from which system;
  • which period it covers;
  • whether filters were applied;
  • whether fields were omitted;
  • whether timestamps were converted;
  • whether annotations were added; and
  • whether the original source records still exist.

This is particularly important with screenshots and dashboards.

A screenshot may show what somebody saw at the time, while still omitting hidden fields, filters, surrounding events or the full record.

Product labels need local meaning

Words such as:

  • user;
  • malicious;
  • compromised;
  • risk;
  • login;
  • location; or
  • device

can mean very specific things inside a product.

Do not assume the ordinary-language meaning is identical to the product's definition.

If an alert says “malicious user”, find out what rule or data produced that label.

Is this a source record, alert, ticket or summary? goes deeper into those layers.

Preserve the supplied item too

Going back to the source does not make the supplied material useless.

Keep the original screenshot, PDF, ticket export or analyst report because it may show:

  • what was known at the time;
  • how the incident was understood;
  • what actions were taken; and
  • which records were available to the responder.

The practical point is: identify the material before interpreting it. Know whether you are looking at a source event, a detection, a working incident record or somebody's explanation of one.

Reference: CIM-002Cyber Incidents & Offender Methods