Quickstart: your first investigation
From sign-in to a reviewable result in six steps.
Last updated · September 2026
On this page
The fastest route to a useful result is a narrow question with a clear scope and enough evidence to distinguish facts from assumptions.
- Choose the operating mode
Select Defensive analysis for telemetry, alerts, incidents, detections, vulnerabilities, or remediation. Select Authorized test for owned assets, approved labs, and explicitly authorized assessment planning.
- Name the case
Use an incident number, engagement identifier, change number, or another reference that a teammate can recognize later.
- Select the assets
Use the mode-specific asset library to constrain the question. Add only relevant sources or targets; do not use a broad label when a narrower one is available.
- Attach evidence
Paste or upload the relevant excerpt. Remove secrets and unrelated personal data. Include timestamps, timezone, source, and collection limitations when available.
- Ask an operator question
Request a bounded deliverable: a triage decision, timeline, hypothesis table, detection rule review, remediation plan, or safe validation plan.
- Review and record
Check the output against the evidence, mark uncertainty, assign an owner, and preserve the result in your case-management process.

