cat 01
[ VERDICT-EVIDENCE ]
Verdict Evidence
Reads Sentinel incident state, the runner's follow-up hunt comments, and the accounts and devices in scope.
e.g.
Evidence, exactly as gathered
Pulls the follow-up hunt results the runner already posted — hunt name, query and rows — so the verdict rests on evidence you can read yourself on the incident.
skills 05
cat 02
[ ALERT-INTAKE ]
Alert & Detection Intake
Alerts across endpoint, identity, email and cloud apps, plus whether Defender already blocked the threat.
e.g.
Did Defender already handle it?
Checks antivirus detections, AMSI triggers, attack-surface-reduction events and tampering attempts — so a threat that was already blocked never reads as an open one.
skills 11
cat 03
[ ENTITY-CONTEXT ]
Entity Context
Device posture and vulnerabilities, user role and sign-in history, file reputation and signer trust, IP activity.
e.g.
One view of an entity
Answers the first question an L1 analyst asks about any device, user, file or IP — health, exposure, who used it, what it touched — without opening four portals.
skills 11
cat 04
[ IDENTITY-TRADECRAFT ]
Identity & Sign-In Tradecraft
Password spray, MFA fatigue, risky and new-country sign-ins, brute force, directory changes, and AD reconnaissance.
e.g.
Spray and fatigue, named
Separates one IP grinding a wrong password across many accounts from a genuine lockout, and catches MFA prompt-bombing that ends in a success.
skills 08
cat 05
[ IDENTITY-PERSISTENCE ]
Identity Persistence Checks
Newly registered devices, app and service-principal changes, consent grants, mailbox rules, exfiltration signals.
e.g.
Did they keep the account?
Run after an identity verdict: the registered device, rogue consent grant or quiet forwarding rule an attacker leaves behind to stay in after the password reset.
skills 05
cat 06
[ ENDPOINT-PERSISTENCE ]
Endpoint Persistence Checks
Registry run keys, service installs, startup-folder drops, scheduled tasks, and WMI event subscriptions.
e.g.
Did they keep the host?
Run after an endpoint verdict: the autorun mechanisms that survive a reboot and quietly re-establish access once the incident is closed.
skills 05
cat 07
[ EMAIL-PHISHING ]
Email & Phishing
Sender history and authentication, campaign blast radius, URL clicks, inbox and forwarding rules, ZAP outcomes.
e.g.
Who else got it, and who clicked
Scopes a phishing campaign to every recipient of the same message, shows who clicked through, and confirms whether auto-purge actually pulled it back.
skills 06
cat 08
[ EXECUTION-NETWORK-EVASION ]
Execution, Network & Evasion
Process ancestry, encoded PowerShell, parent-child mismatches, C2 beaconing, defence tampering and ransomware indicators.
e.g.
Beaconing that looks like nothing
Finds the low-and-slow repetitive callbacks that never trip a single-event rule, with the process and command line that made them.
skills 09
cat 09
[ IOC-LATERAL ]
IOC Pivots & Lateral Movement
Indicator sweeps across all telemetry, attachment tracing, related hosts, remote-execution tooling and logon fan-out.
e.g.
Blast radius from one indicator
Takes a single hash, IP or domain and finds every other host and account that touched it — turning one alert into the real scope.
skills 07