CHAPTER 03 35 MIN READ INTERMEDIATE

Detection and Analysis: Scoping, Evidence & Timelines

This chapter covers PICERL's Identification phase in full: the point where a suspected incident becomes a scoped, evidence-backed investigation. Everything downstream, containment, eradication, recovery, depends on getting scope and evidence right here.

scoping evidence collection chain of custody timeline reconstruction

From SOC Alert to IR Ownership

Not every SOC alert needs full IR treatment. Certain signals mark the point where an incident outgrows SOC-scoped handling and needs to move to dedicated IR ownership.

Handoff TriggerWhy It Exceeds SOC Scope
Multi-system scopeThe activity spans multiple hosts, business units, or environments, beyond what a single analyst can triage in one queue item.
Targeted or persistent actor signsEvidence of deliberate, human-driven intrusion rather than opportunistic or automated malware, which changes both urgency and depth of analysis needed.
Need for forensic-level analysisThe case requires disk, memory, or malware analysis beyond what SIEM and EDR consoles surface on their own.
Legal, regulatory, or reputational stakesAnything that may require notification, litigation hold, or executive briefing needs formal IR process and documentation.
Note: SOC Operations' own workflow chapter covers the triage side of this handoff, how an L1/L2 analyst recognizes these signs and escalates. This chapter picks up where that handoff completes.

Scoping the Incident

Scoping answers one question: how big is this, really? These four concepts are the vocabulary IR teams use to answer it.

Scoping glossary:
  • Patient Zero: the first system or account confirmed compromised, the entry point the rest of the investigation traces forward and backward from.
  • Blast Radius: every system, account, and dataset the attacker could plausibly have reached from patient zero, based on network access and privilege level.
  • Initial Scope vs. Full Scope: initial scope is what's confirmed compromised at handoff; full scope is what investigation eventually proves was actually touched, almost always larger.
  • IOC Pivoting: using a confirmed indicator (a hash, an IP, a domain) to search other systems and logs for the same indicator, expanding scope one confirmed match at a time.
Common mistake: treating initial scope as final scope. Closing an investigation before pivoting on every known IOC is one of the most common ways a "contained" incident reopens weeks later.

Evidence Collection and Chain of Custody

Evidence has to be collected in an order that respects how quickly it disappears, and documented well enough to hold up under scrutiny later.

Order of Volatility (Most to Least Volatile)

#Evidence TypeWhy It's Volatile
1CPU registers and cacheChanges constantly during normal operation; gone the instant power or process state changes.
2RAMLost completely on reboot or shutdown; holds running processes, open network connections, and decrypted data.
3Network stateActive connections and ARP/routing tables change continuously and aren't retained after the session ends.
4Running processesProcess lists and handles exist only while the system stays up.
5DiskPersists through reboot, but can be overwritten by normal disk activity or attacker anti-forensics.
6Remote logging and backupsMost durable; typically retained on separate infrastructure with its own retention schedule.
A chain-of-custody record must capture:
  • Who collected the evidence, by name and role.
  • When it was collected, with exact timestamps.
  • How it was collected, including tool and method used.
  • Hash values (e.g. SHA-256) computed at collection, to prove integrity later.
  • Every handoff: who received the evidence next, and when.

Building an Incident Timeline

A timeline turns scattered evidence into a coherent story of what the attacker did and when. Different sources reveal different parts of that story.

Data SourceWhat It Reveals
EDR process treesParent-child process relationships, showing exactly how a payload was launched and what it spawned afterward.
Authentication logsAccount logons, failed attempts, and privilege use, useful for tracing lateral movement and credential abuse.
Network flow and DNS logsConnections to external infrastructure, including command-and-control beaconing and data staging destinations.
Cloud audit logsAPI calls and configuration changes in cloud environments, often the only record of actions with no endpoint footprint.
File system timestampsCreation, modification, and access times that help place file drops and staging activity in sequence.
1
Collect Timestamps
Pull relevant events from every available source, normalized to a single time zone.
→
2
Sequence Events
Order events chronologically and flag gaps where no telemetry exists.
→
3
Correlate Across Sources
Match events across log types to confirm the same activity from independent angles.
→
4
Validate the Narrative
Check the resulting story against known TTPs and patient zero to confirm it's internally consistent.
Note: Clock drift between systems is a real problem. Normalize every source to UTC before building the timeline, or sequencing conclusions can be wrong by minutes or hours.

Analysis Pitfalls

The same cognitive shortcuts that help analysts move fast under pressure can also quietly wreck an investigation.

Pitfall glossary:
  • Confirmation Bias: favoring evidence that supports an early theory of the incident while discounting evidence that contradicts it.
  • Tunnel Vision: fixating on the first compromised system or IOC found and missing a wider blast radius as a result.
  • Premature Closure: declaring an incident contained or resolved before full scope and root cause are actually confirmed.
  • Ignoring Negative Evidence: dismissing the absence of expected artifacts, when a missing log or artifact can itself indicate anti-forensic activity.
Guardrail: a second analyst reviewing the timeline and scope before closure catches most of these pitfalls. Fresh eyes aren't attached to the first theory.

Key Takeaways

  • An incident moves from SOC ownership to full IR when scope, actor sophistication, or forensic need exceeds what SOC triage covers.
  • Scoping runs on four concepts: patient zero, blast radius, initial vs. full scope, and IOC pivoting.
  • Evidence collection follows the order of volatility, from CPU registers and RAM down to remote logs and backups.
  • Chain of custody must record who, when, how, hash values, and every handoff for evidence to hold up later.
  • A timeline draws on EDR, authentication, network, cloud audit, and file system data, normalized to a single time zone.
  • Confirmation bias, tunnel vision, premature closure, and ignoring negative evidence are the most common ways an analysis goes wrong.

Knowledge Check

Click an answer to reveal the explanation.

During incident response, in which order should evidence generally be collected?

Correct answer: B. The order of volatility exists because the most fragile evidence disappears fastest. Collecting RAM after disk risks losing running-process and network-connection data that a reboot or normal system activity would otherwise erase.

An IR team confirms a single laptop was compromised via a phishing email. The laptop had domain admin credentials cached and network access to the company's file servers. What should the team do next regarding scope?

Correct answer: B. Patient zero is just the starting point. Blast radius is defined by what the compromised system could reach, and cached domain admin credentials with file server access make that reach significant regardless of how the initial compromise happened.

An analyst builds a timeline showing an attacker moved from initial access to data staging in under an hour, and closes the case as fully scoped. A missing DNS log for the affected host during the incident window was never explained. What pitfall does this best illustrate?

Correct answer: B. A gap in expected telemetry is itself a data point. Treating a missing log as a non-issue rather than something to explain is the classic shape of ignoring negative evidence, and it can hide anti-forensic activity or an incomplete timeline.