Key Takeaways
The key focus of an incident response investigation is to create sufficient context to know what to do first before disrupting an incident.
Early evidence preservation is critical for determining what the attacker did and preventing the loss of important evidence during containment.
The first alert is usually not complete, and requires the teams to assess related endpoints, identities, network activity, and systems.
By examining attacker activity in conjunction with IOCs persistence, credential abuse, lateral movement and related activity can be discovered that might not be detected using indicators.
The scope for containment should be based on known activity from the attacker, as well as the scope of the compromise, and should not be just the first identifiable sign.
Once a security team confirms suspicious activity is credible enough to investigate, the challenge is no longer recognizing that an incident may exist. It is deciding what to do first without losing evidence, narrowing the investigation too early, or taking containment actions that expose the response to the attacker.
The first phase of an incident response investigation should therefore focus on building enough situational awareness to make informed decisions. Teams need to validate what is known, preserve critical evidence, determine how far the compromise extends, reconstruct attacker activity, and understand what is at risk before moving into broader containment and remediation.
1. Start With the Trigger, but Do Not Let It Define the Incident
Every investigation starts somewhere: an endpoint detection, suspicious authentication, unusual network connection, malware alert, phishing report, or threat intelligence match. The mistake is assuming that the first detection represents the entire incident.
Treat the triggering event as an investigative lead. Validate whether the activity is malicious and then examine what happened immediately before and after it. A suspicious process, for example, becomes much more meaningful when correlated with an unusual login, credential access, or outbound network communication.
This initial validation should answer three questions: Is the activity genuinely suspicious? Which asset or identity is currently known to be involved? Is there enough evidence to expand the investigation? This is also where correlated visibility can reduce investigation time. Fidelis Elevate® brings together network, endpoint, deception, and Active Directory security capabilities, allowing analysts to investigate related activity with more context instead of treating each detection as an isolated event.
What data has been potentially exposed?
Incursion detection and Persistence detection
How should I respond?
2. Preserve the Evidence You May Need Later
Containment is important, but immediately changing a compromised system can remove valuable evidence. Restarting an endpoint may eliminate volatile information. Reimaging it can remove forensic artifacts. Blocking attacker infrastructure can cause an active adversary to switch techniques or disappear before the security team understands their reach.
Preserve relevant endpoint activity, authentication records, network metadata, DNS activity, process execution history, suspicious files, cloud logs, and other available telemetry before making unnecessary changes. The amount of evidence required will depend on the incident. If a single endpoint is infected with commodity malware, the level of evidence preservation may differ from what is required for ransomware, insider activity, or incidents involving sensitive data.
Historical visibility is especially critical if investigating the detection back to the historical event. Fidelis Network® provides deep visibility into network activity and retains rich metadata that can help investigators examine historical communications and determine whether suspicious behavior occurred before the original alert.
3. Determine the Scope Before Assuming Containment Worked
One of the most important early investigation questions is: Where else should we look?
One endpoint infected doesn’t mean one endpoint is infected. Likewise, blocking one suspicious account does not necessarily mean that the attacker doesn’t have another account. Similarly, disabling one suspicious account does not prove that the attacker has no other credentials. Investigators should pivot outward from the initial detection:
Initial detection → endpoint → identity → related systems → network activity → external infrastructure
Suppose an endpoint shows credential-dumping behavior. The next question is not simply whether the malicious process can be removed. Investigators need to determine which credentials may have been exposed, where those identities are authenticated afterward, and whether those sessions led to additional systems.
Fidelis Endpoint® can provide endpoint-level visibility into suspicious processes and activity, while network visibility can help analysts investigate communications and movement beyond the original host. Connecting those perspectives helps teams determine whether an endpoint event is isolated or part of a broader intrusion. Scope should remain provisional during early investigation. New evidence may continuously expand or narrow the known incident.
4. Find the Earliest Evidence of Attacker Activity
The first event detected is not always indicative of the first event by the attacker. Security teams should work backward from the detection to identify the earliest evidence of malicious activity. Then they can move forward again to reconstruct how the intrusion developed.
For example:
Building this sequence helps distinguish unrelated alerts from connected attacker behavior. It also provides information needed for later decisions. If investigators discover that suspicious activity began only minutes before detection, containment may be relatively straightforward. If they find evidence stretching back several weeks, they need to consider the possibility of established persistence, compromised credentials, and additional access paths.
Historical network metadata and endpoint telemetry can be valuable here because investigators are not limited to what is happening now the incident is detected.
5. Determine Whether You Are Dealing with an Incursion or an Established Presence
This distinction can significantly change the response strategy. A recent incident can affect a relatively small number of systems and have a limited scope of access by the intruder. If the team can determine the point of entry early the containment measures can include isolation of impacted assets, revocation of compromised sessions and blocking of malicious infrastructure.
An established attacker is different. If the adversary has maintained access for days, weeks, or longer, investigators should consider whether additional persistence mechanisms, accounts, credentials, or communication channels exist.
Removing the first malicious artifact may therefore accomplish very little. It can also reveal to the attacker that the organization has discovered them. An adversary who realizes they are being investigated may delete evidence, change infrastructure, accelerate data theft, or activate alternative persistence mechanisms. This is why the first investigation should establish attacker depth before the team assumes that removing the visible indicator removes the threat.
6. Investigate Behaviors, Not Just Known IOCs
Indicators of compromise provide useful starting points. Investigators can search file hashes, IP addresses, domains, URLs, processes, accounts, or command-line patterns across the environment.
But IOCs have limitations. Attackers can rotate domains, change IP addresses, modify files, or use legitimate administrative tools. Searching only for the indicators associated with the original detection may therefore miss related compromise.
The investigation should expand from “Where else does this IOC appear?” to “Where else is this attacker behavior occurring?”
Look for techniques such as unusual credential access, unexpected privilege escalation, suspicious remote administration, abnormal authentication, unusual PowerShell execution, lateral movement, or unexpected external communication.
Mapping observed behaviors to frameworks such as MITRE ATT&CK can also help investigators understand what the attacker may attempt next. Fidelis Elevate supports MITRE ATT&CK-aligned threat detection and investigation, helping analysts connect related techniques across different stages of attacker activity rather than relying only on static indicators.
7. Determine What the Attacker Reached and What Is at Risk
Technical scope and business impact are related, but they are not the same. Two incidents involving a single compromised endpoint can have very different consequences depending on what that endpoint and its associated identity could access.
Investigators should determine whether compromised assets or identities had access to privileged systems, sensitive business information, customer data, intellectual property, cloud resources, Active Directory, backups, financial systems, or security infrastructure.
Identity activity deserves particular attention. If an attacker has compromised privileged credentials, the investigation needs to follow those credentials across the environment rather than focusing solely on the device where the compromise was discovered.
Fidelis Active Directory security capabilities can add context around identity-related threats and help teams identify suspicious activity targeting Active Directory environments. When combined with endpoint and network evidence, this provides a broader view of how an attacker may be moving between identities, systems, and resources.
8. Decide Whether to Observe, Contain, or Escalate
Containment should be based on what the investigation has established—not simply on the existence of an alert. Some situations leave little room for observation. Active ransomware encryption, destructive malware, or immediate risk to critical systems may require rapid isolation.
Other incidents may benefit from a short investigative window before broad containment. Before taking coordinated containment action, responders should understand enough about the affected endpoints, compromised identities, attacker persistence, lateral movement, external communications, and business impact to avoid leaving important access paths untouched.
The goal is not to delay containment. It is to make containment complete enough to matter.
Fidelis Endpoint supports investigation and response actions at the endpoint level, while broader Fidelis detection and investigation capabilities provide the context needed to determine which systems and activity should be prioritized. This allows teams to move from detection to informed response rather than treating every alert as an independent containment event.
9. Define What “Contained” Actually Means
An isolated endpoint does not necessarily mean an incident is contained. Before taking steps toward eradication and recovery, responders should have clear containment criteria.
For instance, the team should be confident that affected systems have been identified, compromised credentials have been resolved, there is some understanding of how the attacker persisted, how they were being blocked, and that their presence is no longer observed elsewhere. This distinction is critical because attackers may regain access through credentials or persistence mechanisms that the initial investigation failed to identify.
Teams should continue monitoring for related behaviors after containment actions are executed and be prepared to reopen scope if new evidence appears.
10. Know When the Investigation Has Outgrown Internal Capacity
Some investigations are too far-reaching or too sensitive for the internal security team to conduct. Outside incident response help might be necessary if the organization is not confident about scope, if privileged infrastructure has been compromised, if ransomware or theft is suspected, or if the attacker appears to have maintained access for an extended period.
Capacity is another consideration. An internal team can be technically knowledgeable in the investigation but may not have the capacity to analyze hundreds of systems, keep evidence, coordinate containment, communicate with executives and still have to keep security operations going.
Fidelis Incident Responders can assist organizations during a complex incident investigation to determine the type and scope of an incident, explore attacker activity, provide containment and remediation support and guide to recovery.
Bringing Investigation Context Together With Fidelis
The first stages of incident response depend heavily on context. Analysts need to move from the initial alert to the affected endpoint, identity, network activity, historical evidence, and related attacker behaviors without losing the connections between them.
Fidelis Elevate® brings together network, endpoint, deception, and Active Directory security capabilities to help security teams detect, investigate, hunt, and respond to threats across the environment. Historical network metadata can support backward-looking investigation, endpoint visibility helps teams examine host activity, identity-focused capabilities provide additional context around Active Directory threats, and response capabilities help analysts act once the incident scope is understood.
For organizations facing incidents that exceed their internal investigative capacity, Fidelis Incident Response Services can provide additional expertise for investigation, containment, remediation, and recovery.
The value during an incident is not simply having more alerts. It is having enough connected evidence to understand what happened and make the next response decision with greater confidence.
Conclusion
The first actions in an incident response investigation should reduce uncertainty, not simply remove the first visible sign of compromise.
Security teams should confirm detection, secure the evidence, assign scope, figure out the attack timeline, understand attacker persistence, track compromised identities, and know the business impact before deciding that the threat has been contained.
What is most important is the transition from responding to an alert to investigating a situation. Alerts indicate the team where suspicious activity was detected. The investigation helps determine how the attacker gained access, how far they progressed, what systems or data they reached, and what actions are required to remove them completely.
When teams establish that context early, containment becomes more precise, eradication becomes more complete, and recovery can begin with greater confidence that the attacker has been removed.
Our customers detect post-breach attacks over 9x Faster
Detect Advanced Threats Before Damage Escalates TrustedCybersecurity Leader for 20+ YearsSee why security teams choose us over other solutionsRequest a DemoRead Datasheet
Frequently Asked Questions
What should be the priority in an incident response investigation?
The priority should be establishing situational awareness. Validate the initial detection, identify what is currently known to be affected, preserve relevant evidence, and begin determining the potential scope. Immediate containment may still be necessary for destructive or rapidly spreading threats, but teams should avoid making unnecessary changes before understanding the available evidence.
Should you isolate a compromised endpoint immediately?
Not always. Immediate isolation makes sense when the endpoint presents an active risk, such as ransomware propagation or destructive activity. In other cases, investigators may need to preserve evidence and determine whether the attacker has moved elsewhere before isolating the system. The decision should reflect the threat, business risk, and potential impact of delaying containment.
How do you determine the scope of a security incident?
Start with the initial detection and pivot across related endpoints, identities, authentication events, network communications, domains, processes, and other available telemetry. Continue expanding the investigation until the team can reasonably determine which systems, accounts, and resources may have been affected.
How far back should incident responders investigate?
There is no fixed period that applies to every incident. Investigators should work backward from the initial detection until they can identify the earliest supported evidence of malicious activity. Historical telemetry and adequate log retention are therefore important for determining attacker’s dwell time and reconstructing the intrusion.
Why shouldn’t incident responders rely only on IOCs?
IOCs such as hashes, IP addresses, and domains can change quickly. Attackers may also use legitimate tools that do not generate obvious malicious indicators. Investigating attacker behaviors and techniques alongside IOCs provides a better chance of identifying related activity across the environment.
When should an organization bring in an external incident response team?
External support should be considered when the internal team cannot confidently determine incident scope, when the compromise involves privileged access or critical infrastructure, when ransomware or data theft is suspected, or when the scale of the investigation exceeds available internal resources.
The post What to Do First in an Incident Response Investigation appeared first on Fidelis Security.
No Responses