You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
-[ ]**Alert data:** The raw event(s) that triggered the alert -- including all available fields (source IP, destination IP, username, hostname, process name, command line, file hash, URL).
55
-
-[ ]**ATT&CK mapping:** If the alert rule maps to a MITRE ATT&CK technique, note the technique ID.
56
+
-[ ]**ATT&CK mapping:** If the alert rule maps to a MITRE ATT&CK technique, note the technique ID, tactic, reviewed ATT&CK version, and technique URL.
57
+
-[ ]**Source-version evidence:** Record whether ATT&CK v19.1 and NIST SP 800-61 Rev. 3 / CSF 2.0 were reviewed for this triage. If an organization still uses legacy ATT&CK v16 or NIST Rev. 2 labels internally, mark them as legacy mappings and verify any currentness claim against the current sources.
56
58
-[ ]**Asset context:** What is the affected asset? (Server, workstation, cloud instance, network device.) What is its business criticality? (Revenue-generating, customer-facing, development, test.)
57
59
-[ ]**User context:** Who is the associated user? (Role, department, normal working hours, recent activity patterns.)
58
60
-[ ]**Historical context:** Has this alert fired before? What was the previous disposition? Has this user or host generated related alerts recently?
@@ -80,7 +82,7 @@ Gather all data associated with the alert. Do not make a disposition decision un
80
82
|**Threat intelligence**| IOC lookups for IPs, domains, hashes, URLs | VirusTotal, OTX, MISP, TI platform |
81
83
|**Previous alerts**| Historical alerts for same user, host, or IOC | SIEM, case management |
82
84
83
-
**NIST SP 800-61 alignment:** This phase corresponds to Section 3.2 "Detection and Analysis" -- specifically the initial analysis and validation of the alert before classification.
85
+
**NIST SP 800-61 Rev. 3 / CSF 2.0 alignment:** This phase supports Detect and Respond activities by collecting event, asset, user, and response-context evidence before classification. If using legacy NIST Rev. 2 lifecycle wording, label it as a legacy crosswalk rather than current NIST guidance.
84
86
85
87
### Phase 2: Correlate
86
88
@@ -91,8 +93,9 @@ Connect the alert data with surrounding context to build a picture of what happe
91
93
1.**Temporal correlation:** What other events occurred on the same host or by the same user within +/- 30 minutes of the alert?
92
94
2.**Lateral correlation:** Are there related alerts on other hosts or from other security tools for the same time period?
93
95
3.**Behavioral correlation:** Does this activity match known ATT&CK technique patterns? Does it match the user's or system's normal behavior baseline?
94
-
4.**Threat intel correlation:** Do any indicators match known threat actor infrastructure, malware campaigns, or published IOCs?
95
-
5.**Kill chain correlation:** Where does this activity fall in the attack lifecycle? Is there evidence of preceding (reconnaissance, initial access) or subsequent (persistence, lateral movement, exfiltration) stages?
96
+
4.**Source-version check:** Is the rule's ATT&CK mapping current for ATT&CK v19.1? If the rule metadata is pinned to v16, verify that the technique, tactic, and URL still match the current Enterprise matrix before using the mapping for priority.
97
+
5.**Threat intel correlation:** Do any indicators match known threat actor infrastructure, malware campaigns, or published IOCs?
98
+
6.**Kill chain correlation:** Where does this activity fall in the attack lifecycle? Is there evidence of preceding (reconnaissance, initial access) or subsequent (persistence, lateral movement, exfiltration) stages?
96
99
97
100
**ATT&CK-based correlation framework:**
98
101
@@ -154,7 +157,7 @@ Determine whether the alert requires escalation and to whom.
154
157
| Alert matches a known active threat campaign | Threat intelligence team + IR team |
155
158
| Multiple correlated alerts suggest a coordinated attack | IR team lead for incident declaration |
156
159
157
-
**NIST SP 800-61 alignment:** This phase corresponds to Section 3.2.6 "Incident Notification" and Section 3.2.7 "Escalation." NIST recommends predefined escalation procedures with clear criteria and contact information.
160
+
**NIST SP 800-61 Rev. 3 / CSF 2.0 alignment:** This phase supports Respond outcomes by documenting the decision, affected context, escalation target, and recommended next response actions. Use current Rev. 3 / CSF 2.0 terminology for new reports, and only use Rev. 2 section references as legacy crosswalk evidence.
158
161
159
162
**Escalation documentation (minimum required):**
160
163
@@ -194,8 +197,8 @@ Produce the triage decision as a structured report:
| Alert rule metadata |[ATT&CK/NIST labels embedded in rule]|[Matches current sources / legacy labels documented / unmapped]|
220
+
211
221
### Affected Entities
212
222
| Entity | Value | Context |
213
223
|--------|-------|---------|
@@ -249,13 +259,14 @@ exclude known-good IP range, adjust threshold.]
249
259
250
260
## 6. Framework Reference
251
261
252
-
### MITRE ATT&CK v16
262
+
### MITRE ATT&CK v19.1
253
263
254
264
For alert triage, ATT&CK provides the shared vocabulary for understanding what adversary behavior the alert represents and what to look for next. Key uses during triage:
255
265
256
266
-**Technique identification:** Map the alert to a specific ATT&CK technique to understand the adversary's objective.
257
267
-**Kill chain positioning:** Determine where the detected activity falls in the attack lifecycle to assess urgency and look for related activity.
258
268
-**Correlation guidance:** Use ATT&CK's tactic flow to predict what an adversary would do before and after the detected technique.
269
+
-**Version verification:** ATT&CK v19.1 is the current ATT&CK website version as of April 28, 2026. Legacy ATT&CK v16/v16.1 mappings should not be reported as current without checking the current technique page, tactic, and source URL.
Alerts that map to later-stage tactics (Lateral Movement, Collection, Exfiltration, Impact) generally warrant higher priority because they indicate deeper compromise.
NIST SP 800-61 Revision 2 (published August 2012) provides the foundational framework for incident handling in organizations. The alert triage process maps to the "Detection and Analysis" phase of the NIST incident response lifecycle:
283
+
NIST SP 800-61 Rev. 3 (published April 2025) supersedes Rev. 2 and reframes incident response recommendations as a CSF 2.0 Community Profile. For alert triage, use Rev. 3 / CSF 2.0 as the current source baseline:
273
284
274
-
**NIST Incident Response Lifecycle:**
285
+
**Current CSF 2.0 mapping for alert triage:**
275
286
276
-
| Phase | Description | Triage Relevance |
277
-
|-------|-------------|------------------|
278
-
| 1. Preparation | Establishing IR capability, tools, procedures | Defines triage playbooks and escalation paths |
279
-
| 2. Detection and Analysis | Identifying and validating potential incidents |**Primary triage phase** -- collect, correlate, classify |
280
-
| 3. Containment, Eradication, and Recovery | Limiting damage, removing threat, restoring operations | Post-triage for confirmed TPs |
281
-
| 4. Post-Incident Activity | Lessons learned, metric collection, process improvement | Feeds back into triage process improvement |
287
+
| CSF 2.0 Function | Triage Relevance |
288
+
|-------|------------------|
289
+
| Detect | Collect and correlate alert, telemetry, asset, user, and threat-intelligence evidence before deciding disposition. |
290
+
| Respond | Classify priority, document rationale, communicate escalation, and hand off confirmed true positives for response. |
291
+
| Recover / Govern | Preserve triage evidence for lessons learned, metrics, policy updates, and future playbook tuning. |
282
292
283
-
**Key NIST 800-61 Rev 2 recommendations for triage:**
293
+
**Legacy Rev. 2 crosswalk:**
284
294
285
-
-**Section 3.2.4 -- Incident Analysis:** Use multiple data sources for correlation. Do not rely on a single alert in isolation.
286
-
-**Section 3.2.5 -- Incident Documentation:** Document all triage decisions, evidence, and rationale. Maintain an incident log from the first alert.
287
-
-**Section 3.2.6 -- Incident Prioritization:** Prioritize based on the functional impact, information impact, and recoverability of the incident.
288
-
-**Section 3.2.7 -- Incident Notification:** Notify designated personnel based on predefined criteria. Over-communication is preferred to under-communication during active incidents.
295
+
Older programs may still refer to NIST Rev. 2 "Detection and Analysis" and "Incident Notification" sections. These labels can be useful for continuity, but they are superseded by Rev. 3 and should be recorded as legacy crosswalk evidence in new triage reports.
@@ -317,7 +324,11 @@ Investigating an alert in isolation without checking for activity before and aft
317
324
318
325
### Pitfall 5: Delaying Escalation While Seeking Perfect Information
319
326
320
-
Waiting for complete certainty before escalating a high-priority alert costs response time. NIST SP 800-61 recommends erring on the side of over-notification. If 20 minutes of investigation has not resolved the disposition and the alert involves a critical asset or privileged account, escalate to Tier 2 or the IR team with your current findings and continue investigation in parallel.
327
+
Waiting for complete certainty before escalating a high-priority alert costs response time. If 20 minutes of investigation has not resolved the disposition and the alert involves a critical asset or privileged account, escalate to Tier 2 or the IR team with your current findings and continue investigation in parallel.
328
+
329
+
### Pitfall 6: Treating Legacy Framework Labels as Current Evidence
330
+
331
+
Many detection rules still embed ATT&CK v16 or NIST SP 800-61 Rev. 2 labels. Do not copy those labels into a triage report as current framework evidence without verifying them against ATT&CK v19.1 and NIST SP 800-61 Rev. 3 / CSF 2.0. If the rule metadata has not been refreshed, mark the mapping as legacy and include the reviewed current-source date.
321
332
322
333
---
323
334
@@ -335,12 +346,13 @@ This skill processes user-supplied content that may include alert payloads, log
0 commit comments