Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

How to Start a Security Investigation from an Alert

N-able
05/11/2026
10
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


TL;DR

  • MDR platforms ingest logs from endpoints, cloud providers, and network appliances to provide comprehensive visibility across the entire IT environment for security investigations
  • Thorough documentation is critical during investigations — analysts should timestamp every finding, command, and hypothesis so others can reconstruct the investigation and verify all angles were explored
  • System enumeration alerts on internal machines indicate an attacker has already breached perimeter defenses, not initial reconnaissance, requiring immediate investigation of how they gained access
  • Analysts use logon IDs and session IDs from alert details to pivot and trace related suspicious activities within the same user session across the environment

MDR Platform Investigation Workflow

This demonstration walks through the initial stages of a security investigation using an MDR (Managed Detection and Response) platform that functions as an advanced SIEM. The platform ingests logs from multiple sources including Windows and Linux endpoints, cloud providers like Azure and AWS, and network appliances via syslog. The session emphasizes the critical importance of documentation during investigations, showing how analysts use investigation managers to create case files, timestamp findings, and maintain detailed notes that allow others to reconstruct the investigation process. The instructor stresses that thorough documentation is essential not just for compliance and potential legal proceedings, but for ensuring no investigative angles are left unexplored.

Analyzing System Enumeration Alerts

The demonstration focuses on triaging a specific alert for system enumeration detection involving the execution of ipconfig.exe from an administrator account. The analysis reveals this is likely not reconnaissance against a public-facing asset, but rather indicates an attacker who has already breached internal defenses and is now mapping the internal network. The instructor explains how to examine alert details including file authenticity, integrity levels, and execution context to determine whether legitimate Microsoft binaries are being used in a living-off-the-land attack. Key investigative techniques include using logon IDs and terminal session IDs to pivot and identify related activities within the same session, while being mindful of the volume of logs generated by servers when setting time windows for investigation.

Chapters

0:00 - MDR Platform Overview
1:23 - Investigation Documentation Best Practices
2:32 - Creating an Investigation Case
4:54 - Triaging System Enumeration Alert
6:55 - Analyzing Alert Evidence and Context
8:38 - Using Log IDs for Pivoting
9:45 - Time Window Considerations for Log Analysis

Key Quotes

3:10 "When I'm doing an investigation or an IR, or even like an operation, right? Like I have a text file, I'm like timestamping everything, like every command I look at every directory, I'm looking at like, my thoughts, like in hypotheses, right? Like, it should be like a detective, right? You have to have case notes, right? ..."
4:09 "I know actually like some really good threat, like, what do you call it, like incident response people, like the folks who are like, you know, out there doing the Fortune 500 responses when they happen, you know, like no time to spare, like billions of dollars of risk. They actually use like voice recorders, just like you would see like a medical examiner use."
5:48 "So they think that could be, cause yes, right? They think that this could be considered a portion of the reconnaissance stage. And like, that may be the case if this was a public facing asset, right? But like, we know our network. We don't see a source IP here indicating that it's a public machine. Like we know how to read these logs. Like this is an internal machine. So like, if somebody's already scanning it, they've already breached some defense layer."
8:42 "We're going to see like the log on ID, the terminal session ID, and then we can use these values to pivot, right? And see, were there any other activities taken in this same log on or, you know, in the same session? ..."

Categories:
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Security Operations
  • Threat Intelligence
  • Technical Deep Dive
  • Demo
  • How-To
  • MDR platforms
  • Security investigation workflow
  • Alert triage
  • System enumeration detection
  • Living off the land attacks
  • Incident response documentation
  • Log analysis techniques
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: How to Start a Security Investigation from an Alert

              Upcoming Webinar Calendar

              • 06/10/2026
                11:00 AM
                06/10/2026
                Action1: Vulnerability Digest--Patch Tuesday & Other Updates
                https://www.truthinit.com/index.php/channel/1997/action1-vulnerability-digest-patch-tuesday-other-updates/
              • 06/10/2026
                02:00 PM
                06/10/2026
                Understanding the True Costs of DIY Data Classification vs. Buying Solutions
                https://www.truthinit.com/index.php/channel/1985/understanding-the-true-costs-of-diy-data-classification-vs-buying-solutions/
              • 06/23/2026
                10:00 AM
                06/23/2026
                Stay Informed on the Latest Keepit Partner Developments – June 23
                https://www.truthinit.com/index.php/channel/1990/stay-informed-on-the-latest-keepit-partner-developments-–-june-23/
              • 06/25/2026
                01:00 PM
                06/25/2026
                Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier
                https://www.truthinit.com/index.php/channel/1998/generative-ai-security-preventing-ai-from-becoming-a-data-breach-multiplier/

              Upcoming Events

              • Jun
                10

                Action1: Vulnerability Digest--Patch Tuesday & Other Updates

                06/10/202611:00 AM ET
                • Jun
                  10

                  Understanding the True Costs of DIY Data Classification vs. Buying Solutions

                  06/10/202602:00 PM ET
                  • Jun
                    23

                    Stay Informed on the Latest Keepit Partner Developments – June 23

                    06/23/202610:00 AM ET
                    • Jun
                      25

                      Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier

                      06/25/202601:00 PM ET
                      More events
                      Truth in IT
                      • Sponsor
                      • About Us
                      • Terms of Service
                      • Privacy Policy
                      • Contact Us
                      • Preference Management
                      Desktop version
                      Standard version