Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
Scope, Escalate, Conclude
TheoryHard13 minAnalyst ReportingIncident Triage

Escalate and Hand Over

What is it?

Escalation is the decision to move a case to a higher tier or to incident response, on defined thresholds, with a handover package the receiver can act on immediately: the finding, the scope, the evidence, the confidence, and the specific next actions.

Why it matters

Escalate too late and the intrusion spreads while you gather 'a bit more certainty'; escalate everything and the higher tier drowns and stops trusting you. A poor handover makes the receiver redo your whole investigation. The escalation decision and the handover are where a senior analyst's judgment is most visible.

Where you see it

In the escalation criteria (thresholds: confirmed compromise of a privileged account, data exfiltration, spread beyond one host) and in the handover ticket that IR or the next shift picks up.

What normal looks like

Escalation fires on a pre-agreed threshold, not on a feeling, and the handover is a self-contained package: someone who has never seen the case can read it and take the next action without asking you a question.

What suspicious looks like

An escalation with no scope or evidence attached ('something bad on WS-19, please look'), or a case sat on past its threshold because the analyst wanted more certainty first — both are failures of the escalation discipline.

How analysts investigate

Compare the case against the escalation thresholds; if any is met, escalate now even with open unknowns. Build the handover: finding, scope (confirmed + potential), the cited evidence, severity/confidence, and a numbered next-actions list. The test: could the receiver act without asking you anything?

Common beginner mistakes

  • Holding an incident that already met an escalation threshold to gather more certainty, while it spreads.
  • Escalating with no evidence or scope attached, forcing the receiver to restart the investigation.

The handover package

  • Finding + severity + confidence (from Module 1 and 5.1).
  • Scope: confirmed reach and potential reach, each with its evidence.
  • Cited evidence (source · time · id) and the ruled-out benign explanation.
  • Numbered next actions + the open unknowns.

Worked example. Threshold met: a privileged account (svc-backup) is confirmed compromised and data left the network — that is an automatic IR escalation, regardless of remaining unknowns. Handover: 'Finding: svc-backup compromised, ~4 GB exfiltrated from FS-02 (high severity, high confidence). Scope: confirmed WS-19, FS-02; potential FS-01/03–09 (same access, unchecked). Evidence: identity 5A9, Sysmon 11 on FS-02, proxy 77C. Next actions: (1) disable svc-backup, (2) isolate WS-19 & FS-02, (3) check FS-01/03–09 for the archive pattern, (4) hunt Office→script across the estate. Unknowns: initial access vector.' IR can start immediately from that alone.

Quick check

You have confirmed a privileged account is compromised and data left the network, but you have not yet found the initial access vector. What do you do?

A quick self-check — it doesn't affect your XP or progress.

Sign in to save your progress on the server.