Escalate and Hand Over
What is it?
Escalation is the decision to move a case to a higher tier or to incident response, on defined thresholds, with a handover package the receiver can act on immediately: the finding, the scope, the evidence, the confidence, and the specific next actions.
Why it matters
Escalate too late and the intrusion spreads while you gather 'a bit more certainty'; escalate everything and the higher tier drowns and stops trusting you. A poor handover makes the receiver redo your whole investigation. The escalation decision and the handover are where a senior analyst's judgment is most visible.
Where you see it
In the escalation criteria (thresholds: confirmed compromise of a privileged account, data exfiltration, spread beyond one host) and in the handover ticket that IR or the next shift picks up.
What normal looks like
Escalation fires on a pre-agreed threshold, not on a feeling, and the handover is a self-contained package: someone who has never seen the case can read it and take the next action without asking you a question.
What suspicious looks like
An escalation with no scope or evidence attached ('something bad on WS-19, please look'), or a case sat on past its threshold because the analyst wanted more certainty first — both are failures of the escalation discipline.
How analysts investigate
Compare the case against the escalation thresholds; if any is met, escalate now even with open unknowns. Build the handover: finding, scope (confirmed + potential), the cited evidence, severity/confidence, and a numbered next-actions list. The test: could the receiver act without asking you anything?
Common beginner mistakes
- Holding an incident that already met an escalation threshold to gather more certainty, while it spreads.
- Escalating with no evidence or scope attached, forcing the receiver to restart the investigation.
The handover package
- Finding + severity + confidence (from Module 1 and 5.1).
- Scope: confirmed reach and potential reach, each with its evidence.
- Cited evidence (source · time · id) and the ruled-out benign explanation.
- Numbered next actions + the open unknowns.
Worked example. Threshold met: a privileged account (svc-backup) is confirmed compromised and data left the network — that is an automatic IR escalation, regardless of remaining unknowns. Handover: 'Finding: svc-backup compromised, ~4 GB exfiltrated from FS-02 (high severity, high confidence). Scope: confirmed WS-19, FS-02; potential FS-01/03–09 (same access, unchecked). Evidence: identity 5A9, Sysmon 11 on FS-02, proxy 77C. Next actions: (1) disable svc-backup, (2) isolate WS-19 & FS-02, (3) check FS-01/03–09 for the archive pattern, (4) hunt Office→script across the estate. Unknowns: initial access vector.' IR can start immediately from that alone.
Quick check
You have confirmed a privileged account is compromised and data left the network, but you have not yet found the initial access vector. What do you do?
A quick self-check — it doesn't affect your XP or progress.
Sign in to save your progress on the server.