From Handling Alerts to Owning Cases
What is it?
Owning a case means you are accountable for a question — 'did this account get compromised, and how far did it reach?' — not just for clearing one alert from a queue. You decide the scope of the question, what evidence would answer it, and when it is answered.
Why it matters
An alert-handler closes tickets; a case-owner closes questions. If nobody owns the question, an intrusion becomes a pile of individually-benign, individually-closed alerts and no one ever asks whether they are one story.
Where you see it
In the case-management system, where a senior analyst is assigned an investigation with a stated objective, and in the analyst's own framing note that turns 'alert LD-4821 fired' into 'is host WS-19 compromised, by whom, and what did they reach?'.
What normal looks like
A well-owned case has a written question at the top, a scope (which hosts, accounts and time window are in play) and an explicit finish line: the evidence that would let you conclude either way.
What suspicious looks like
A case with no stated question drifts: the analyst chases whatever is easiest to look at, stops when tired rather than when finished, and writes a conclusion the evidence does not actually support.
How analysts investigate
Write the question first. State the scope and the finish line. Then gather evidence toward that question, and keep asking 'does this move me toward answering the question, or am I just collecting?'.
Common beginner mistakes
- Starting to pull logs before writing the question, so the investigation has no finish line and never really ends.
- Treating the alert's literal text as the whole scope, instead of the entity and blast radius behind it.
What you will be able to do
- Turn an alert into an investigation question with a scope and a finish line.
- Tell the difference between clearing a queue and closing a question.
- Recognise when a case has drifted off its own question.
Worked example. Alert LD-4821: 'impossible travel for j.rai'. A handler confirms the sign-in and closes it as a VPN artefact. A case-owner writes the question — 'is j.rai's account compromised, and what did it touch?' — sets scope to that account plus the hosts it authenticated to over 48 hours, and the finish line to 'either a benign explanation for every anomalous action, or a chain of attacker actions'. That reframing is the difference between closing a ticket and finding the intrusion behind it.
ALERT ─────────────▶ QUESTION ────────▶ SCOPE ───────▶ FINISH LINE
"impossible travel "is j.rai account j.rai benign for every
for j.rai" compromised, + hosts it anomaly, OR a
and what did touched, 48h chain of attacker
it reach?" window actions
(handler stops here) (owner starts here) ─────────────────────────────▶Quick check
An alert reads 'PowerShell spawned by winword.exe on WS-19'. Which is the better investigation question to own?
A quick self-check — it doesn't affect your XP or progress.
Sign in to save your progress on the server.