Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
Owning the Investigation
TheoryHard12 minAnalyst ReportingIncident Triage

The Analyst's Conclusion

What is it?

The conclusion is the product of the investigation: a short written statement of what happened, the evidence that supports it, the confidence you hold, and what you recommend. Everyone downstream — the next shift, the IR lead, an executive — acts on this, not on your raw logs.

Why it matters

A brilliant investigation with a vague conclusion is a failed investigation: nobody can act on 'looks suspicious, maybe compromised'. The conclusion is where senior analysts are actually measured, because it is the only part most readers ever see.

Where you see it

The case conclusion field, the escalation ticket, and the shift-handover note. Same content, tuned length: one line for the handover, a paragraph with evidence references for the case, a scoped recommendation for the escalation.

What normal looks like

A good conclusion states the finding, cites the specific evidence (source, timestamp, id), gives an explicit confidence, names the benign explanation it ruled out, and ends with a clear recommended action.

What suspicious looks like

A conclusion with adjectives instead of evidence ('clearly malicious'), no confidence, no cited artefacts, and no recommendation — a reader cannot verify it or act on it.

How analysts investigate

Write finding, evidence, confidence, ruled-out explanation, recommendation — in that order. If you cannot cite an artefact for a sentence, it is an assumption, and it goes in a separate 'unknowns' line, not in the finding.

Common beginner mistakes

  • Writing conclusions full of confidence adjectives ('definitely', 'obviously') but with no cited evidence a reader can check.
  • Hiding the unknowns to make the conclusion look stronger, so the next analyst re-does work you already knew was open.

The shape of a conclusion

  • Finding: what happened, in one sentence.
  • Evidence: the specific artefacts (source · time · id) that support it.
  • Confidence + ruled-out benign explanation.
  • Recommendation: the action you advise, and the unknowns that remain.

Worked example. Weak: 'j.rai is clearly compromised and stole data — escalate.' Strong: 'Finding: j.rai's account was compromised and used to exfiltrate ~4 GB from the finance share. Evidence: identity sign-in from ASN 20xx at 02:14 (id 5A9), endpoint archive creation on FS-02 at 02:41 (Sysmon 11), proxy POST 4.1 GB to 203.0.113.44 at 02:53 (id 77C). Confidence: high — three independent sources in causal order; ruled out backup (no scheduled job in the window). Recommendation: disable j.rai, isolate FS-02, open IR. Unknowns: initial access vector not yet identified.' The second is actionable and verifiable; the first is neither.

Quick check

Which line belongs in the 'unknowns' section rather than the 'finding'?

A quick self-check — it doesn't affect your XP or progress.

Sign in to save your progress on the server.