Alert Reporting

Alert Funnel

Pasted image 20251208114953.png

Alert Reporting

Before closing or passing the alert to L2, you might have to report it. Depending on team standards and alert severity, instead of a short alert comment, you can be required to document your investigation in detail, ensuring all relevant evidence is included. This is especially important for True Positives, which require escalation.

Alert Report Purpose

Report Format

Alert Escalation

If the True Positive alert requires additional actions or deeper investigation, escalate it to the L2 analyst for further review following the agreed procedures. That's where your alert report comes in handy since L2 will use it to get the initial context and spend less on the analysis from scratch.

You should escalate the alerts if:

  1. The alert is an indicator of a major cyberattack requiring deeper investigation orĀ DFIR
  2. Remediation actions like malware removal, host isolation, or password reset are required
  3. Communication with customers, partners, management, or law enforcement agencies is required
  4. You just do not fully understand the alert and need some help from more senior analysts

Escalation Steps

To escalate the alert, in most cases, all you have to do is toĀ reassign the alert to the L2 on shiftĀ and ping them in corporate chat or in person. In some teams though, you may be required to create a formal written escalation request with dozens of required fields.

No matter what the agreements are, L2 will eventually receive the ticket from you, read your report, and contact you in case of any questions. Once everything is clear, the L2 analyst will typically research the alert details further, validate if the alert is indeed a True Positive, communicate with other departments if needed, and, for major incidents, start a formalĀ Incident Response process.

Requesting L2 Support

It is generally fine for L1 to request senior support if something is unclear. Especially in your first months, it's always better to discuss the alert and clarifyĀ SOCĀ procedures than to blindly close the alert you don't understand yourself.

Communication

You may also need to communicate with other departments during or after the analysis. For example, ask the IT team if they confirm granting administrative privileges to some users or contact HR to get more information about the newly hired employee.

The escalation and reporting topics should sound straightforward and logical to you. But, as always, it's easier said than done, and you should be prepared for unexpected scenarios and know what to do in critical cases. In the best scenario, theĀ SOCĀ team has its ownĀ Crisis CommunicationĀ procedures - the guides and processes to help you and your teammates resolve the issues. If not, you are advised to read the cases below and be prepared to handle them effectively.

Communication Cases

Pasted image 20251208121532.png