# Alert fires in SIEM (Splunk / QRadar / Microsoft Sentinel)
Step 1: ACKNOWLEDGE the alert
- Mark in-progress in your ticketing system
Step 2: READ the alert
- What rule triggered?
- Which asset / user is affected?
- Severity level? (Critical / High / Medium / Low)
Step 3: GATHER CONTEXT
- Source IP → internal or external?
- Lookup: VirusTotal, AbuseIPDB, Shodan
- User account → service account? admin? new?
- Time → business hours? First occurrence?
Step 4: CORRELATE events
- Did same IP / user trigger OTHER alerts?
- Look ±30 min around the event
- Check firewall logs, DNS, EDR
Step 5: DETERMINE verdict
- True Positive → Escalate to Tier 2, document findings
- False Positive → Document WHY, close, suggest rule tuning
Step 6: DOCUMENT everything
- Ticket: what you found, what you checked, decision rationale
IAM changes, S3 public bucket, API calls from new region
5. Windows Event IDs Cheat Sheet
# Authentication
4624 - Successful logon
4625 - Failed logon ← many within short time = brute force
4634 - Logoff
4648 - Explicit credential use (runas)
# Account Management
4720 - User account created
4722 - User account enabled
4728 - User added to global security group
4732 - User added to local Administrators ← suspicious!
# Privilege / Process
4672 - Admin privileges assigned to new logon
4688 - New process created ← watch: powershell, wscript, mshta
4698 - Scheduled task created
# Audit
1102 - Audit log cleared ← RED FLAG
4719 - Audit policy changed
# Splunk hunt for brute force:
index=wineventlog EventCode=4625
| stats count by src_ip, Account_Name
| where count > 10
| sort -count
6. Vulnerability Management Lifecycle
1. DISCOVER → Scan assets (Nessus, Qualys, OpenVAS)
2. PRIORITIZE → Score with CVSS, add context
3. REMEDIATE → Patch, configure, or mitigate
4. VERIFY → Re-scan to confirm fix
5. REPORT → Track metrics, present to leadership
# CVSS v3.1 Severity Ranges
Critical 9.0-10.0 → patch within 24-72 hours
High 7.0-8.9 → patch within 1-2 weeks
Medium 4.0-6.9 → patch within 30 days
Low 0.1-3.9 → next maintenance window
# Prioritization factors BEYOND CVSS score:
# ✔ Internet-facing?
# ✔ Known exploit in the wild? (CISA KEV list)
# ✔ Sensitive data at risk?
# ✔ Exploitable without authentication?
# ✔ Business-critical service?
7. Incident Response Lifecycle
Phase
Actions
1. Preparation
IR plan, playbooks, tools, contacts, tabletop exercises
2. Detection & Analysis
Alert triage, IOC identification, scope the incident
3. Containment
Isolate systems, block IOCs at firewall/DNS, reset creds
4. Eradication
Remove malware, close vulnerabilities, clear persistence
5. Recovery
Restore from backup, verify clean state, monitor closely