L1 VALIDATION Β· L2 INVESTIGATION Β· ESCALATION

SOC Alert Triage

A repeatable L1 and L2 alert triage runbook for validating signals, scoping impact, preserving evidence, and escalating cleanly.

Triage is a decision process: validate the signal, establish scope, contain confirmed risk, and leave an investigator a clean trail.

PHASE 01

L1 validate the alert

Check source reliability, timestamps, user and host context, baseline behavior, and whether the detection logic actually matched.

  • Record alert ID, rule version, and raw event IDs.
  • Identify obvious false-positive patterns before escalating.
  • Do not close without a reason and evidence.

PHASE 02

L2 scope and investigate

Pivot by account, host, IP, process, and time window. Build a short timeline that separates observed facts from assumptions.

  • Check identity, endpoint, network, and cloud telemetry.
  • Search for similar activity across the environment.
  • Preserve relevant logs before retention expires.

PHASE 03

Escalate or close cleanly

Escalate with impact, confidence, scope, actions taken, and the next decision needed. Closure should improve future detection quality.

  • Name the incident owner and containment status.
  • Add false-positive tuning notes or a detection gap.
  • Link evidence, tickets, and communication records.

Frequently asked questions

What makes an alert high priority?

Confirmed malicious behavior, sensitive asset impact, privileged identities, active spread, or evidence of data access raise priority.