Memory hook: A relationship suggests a path; evidence proves the event.
Must remember
Multi-stage attacks connect initial access, identity abuse, lateral movement, persistence and impact. Build a timeline with stable entities, source provenance and confidence. A privileged relationship can reveal possible blast radius even when no malicious traversal has yet been observed.
Hunting graphs and Sentinel Graph help examine relationships among supported entities. Distinguish a possible attack path from an observed sequence. A user with access to a server is not proof that the user accessed it during the incident. Correlate graph context with sign-ins, process/network events and other relevant records.
Embedded Security Copilot and supported agentic capabilities can summarize incidents, explain queries and suggest investigation steps. Check every consequential claim against cited evidence and actual tool output. A fluent narrative can join unrelated entities or omit telemetry gaps. Data inside email, documents and logs can contain adversarial instructions; it remains evidence to analyze, not authority over the workflow.
Case management preserves ownership, status, tasks and evidence across a complex investigation. Separate facts, hypotheses and decisions. Assign follow-up for missing evidence, document containment scope and track recovery validation. An automated summary is a convenience, not the authoritative chain of custody.
Under exam pressure, choose the action that reduces the immediate risk while preserving necessary evidence and respecting permissions. Broader containment can be justified for active compromise, but a vague low-confidence signal does not justify disabling an entire organization. Reassess scope as evidence changes and record why the response expanded or narrowed.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Estimate what a compromised identity could reach | Relationship/attack-path analysis, validated against access configuration. |
| Prove it actually moved laterally | Correlated time-bound activity evidence. |
| Copilot proposes a response | Validate evidence, scope, authorization and operational impact. |
Traps
- A graph edge is not necessarily an observed attack step.
- A confident generated summary can still be wrong.
Active recall
1. Potential path versus observed movement?
Access relationships describe possibility; event evidence supports what occurred.
2. Why preserve entity IDs?
Display names and addresses may be reused or ambiguous.
3. What should an AI summary cite?
The actual records and entities supporting its claims.
4. Why separate hypotheses from facts?
To prevent an unverified assumption from becoming accepted incident history.
5. What should recovery validation establish?
The threat is addressed and business service can resume without recreating the compromise.