| Is this actually a breach? |
Correlated endpoint, network, identity, cloud, behavioral, deception, and threat intelligence evidence |
Whether to escalate from a security incident into the formal breach process |
| Where did the attacker enter and how far did they get? |
Session history, process activity, authentication behavior, lateral movement, exploited assets, command-and-control activity |
Containment scope and investigation priorities |
| What data was affected? |
Content-aware network inspection, data movement, user activity, affected repositories, transfer destinations and sessions |
Legal assessment, notification decisions and business impact analysis |
| Has the attacker been contained? |
Endpoint status, network communication, compromised identities, cloud workload activity, persistence mechanisms |
Whether containment can move into eradication |
| Is it safe to recover? |
Retrospective searches, IOC sweeps, forensic validation and monitoring of affected infrastructure |
Restoration, business resumption and final incident closure |