> For the complete documentation index, see [llms.txt](https://docs.cybaops.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.cybaops.com/modules/detect-and-respond-mdr/self-hosted-soc/phase-2-investigation-core-loop.md).

# Phase 2: Investigation: Core Loop

{% hint style="info" %}

#### Iterative Phase

This is the heart of Detect and Respond. Everything in Phase 2 is artefact-driven, timeline-first, continuously documented, and platform-enforced.

This loop continues unitl analytical confidence is achieved. You may cycle through Steps 1 to 6 multiple times before reaching a conclusion.
{% endhint %}

## <mark style="color:$primary;">Step 1: Review Initial Artefacts</mark>

When you open a case, review all automatically-added artefacts in the Artefacts panel on the right side of the case view. These may include user accounts, IP addresses, external URLs, files, and hashes.

<figure><picture><source srcset="/files/duuNTT1bbGQJtHuB9id1" media="(prefers-color-scheme: dark)"><img src="/files/MVgOHYZvm3gUB2emnxAE" alt=""></picture><figcaption></figcaption></figure>

For each artefact, open the detail view and apply an initial assessment using the Assessment control:

<table><thead><tr><th width="130">Assessment</th><th>When to Use</th></tr></thead><tbody><tr><td>Benign</td><td>Activity is normal and expected. No threat present.</td></tr><tr><td>Suspicious</td><td>Activity is unusual or unexpected. Further investigation required.</td></tr><tr><td>Malicious</td><td>Activity is confirmed malicious or a direct indicator of compromise.</td></tr><tr><td>Not assessed</td><td>Not yet assessed by an analyst</td></tr></tbody></table>

<figure><picture><source srcset="/files/mnZ7IreGvNbhmEMqqwCa" media="(prefers-color-scheme: dark)"><img src="/files/uQ7dex3WkH2CdWIQsbc5" alt=""></picture><figcaption></figcaption></figure>

{% hint style="info" %}
Where detection logic has provided an intial assessment, review it and confirm or override as approriate. Remember: the initial artefacts reflect what the detection rule matched on. They are a starting point

#### Minimum Requirements / Gate

* Every artefact must be assessed before the case can be resolved
  {% endhint %}

## <mark style="color:$primary;">Step 2: Investigation starts - (Investigate SIEM)</mark>

Click the Investigate button at the top of the case to pivot into the SIEM. Query logs and events to build context not present in the original alert. You should be able to view all logs from your connectors in here without pivoting to each individual tool.

<figure><picture><source srcset="/files/qO8IE5PDZEG4wOtc6Tuz" media="(prefers-color-scheme: dark)"><img src="/files/y9glPi779PP1KgjHh9fI" alt=""></picture><figcaption></figcaption></figure>

You can write queries directly in syntax, or click the stars next to the search bar to have AI perform a free text search. There are two different types of AI search, Quick Search and Reasoned Search - click their names to switch between the two. Quick search is fast, reasoned search is slower, but overall more accurate. Click the stars again to convert your search back to syntax.

All events are normalised to OCSF format, so use this to structure your syntax searches.

Typical investigation queries include authentication activity, conditional access changes, policy modifications, and session behaviour. Results can be viewed as an event list or grouped and visualised as time charts and pie charts to help spot anomalies across large data sets.

<figure><picture><source srcset="/files/54HMgfyHH3bWOqKcg3rj" media="(prefers-color-scheme: dark)"><img src="/files/3x2hBbstIUgqv5SmRLqw" alt=""></picture><figcaption></figcaption></figure>

{% hint style="info" %}

#### Tip: Using Quick Search to Learn Syntax

Quick Search and Reasoned Search includes an AI-assisted mode. You can type what you are looking for in plain English and the platform will run the query. If you then toggle off the AI mode, it will show you equivalent syntax query it ran.

This is a useful way to build your query-writing skills over time. Use it to understand how the platform translates your intent into structured searches, and gradually start writing syntax directly as your confidence grows.
{% endhint %}

## <mark style="color:$primary;">Step 3: Expanded Artefacts</mark>

As you investigate, extract new evidence from logs and action as needed.

When  hovering over data within an event, you are presented with a number of options:

* The plus icon - this adds the value to your search query&#x20;
* The minus icon - Excludes any events with that value for that property
* The copy icon - copies the data
* The data ingestion icon - this adds the data you have selected to the timeline for the investigation

<figure><picture><source srcset="/files/kG1n5gLRdq9GZd4BdbY9" media="(prefers-color-scheme: dark)"><img src="/files/6M0gHq2D8dZzobEysRsv" alt=""></picture><figcaption></figcaption></figure>

All evidence relied upon in your conclusions exist as artefacts in the case.

<figure><picture><source srcset="/files/MQ3LuT3pQnfDX3vMedP4" media="(prefers-color-scheme: dark)"><img src="/files/bos1EWuL7jiMv2KKf7Sp" alt=""></picture><figcaption></figcaption></figure>

#### <mark style="color:$primary;">Artefact Enrichment</mark>

When you add IP addresses, URLs, or file hashes, the platform enriches them automatically with threat intelligence data including geolocation, threat verdicts, and known TTPs. This enrichment happens in the background and the results appear directly on the artefact.

{% hint style="info" %}

#### Minimum Requirements / Gate

* All evidence relied upon in your conclusion must exist as artefacts in the case
* Mental or undocumented evidence is not permitted. If you used it, it must be in the case
  {% endhint %}

## <mark style="color:$primary;">Step 4: Assess Artefacts (Continuous)</mark>

Continuously update artefact assessments as your understanding evolves. This is not a one-time action. Reassess artefacts whenever new evidence changes the picture.

Use the Assessment control on each artefact to assign Benign, Suspicious, or Malicious.

<figure><picture><source srcset="/files/mnZ7IreGvNbhmEMqqwCa" media="(prefers-color-scheme: dark)"><img src="/files/uQ7dex3WkH2CdWIQsbc5" alt=""></picture><figcaption></figcaption></figure>

## <mark style="color:$primary;">Step 5: Category, Subcategory and MITRE Mapping</mark>

Classification must be kept current throughout the investigation. Update Category, Subcategory and MITRE ATT\&CK mappings continuously as your understanding evolves.

The MITRE ATT\&CK section appears in the Incident Overview panel. Click "Manage MTRE ATT\&CK" to add or update tactics and techniques.

<figure><picture><source srcset="/files/X68L5x8zlll8aaOucZ85" media="(prefers-color-scheme: dark)"><img src="/files/6gzLloWnZ6zJA8IYJbbd" alt=""></picture><figcaption></figcaption></figure>

<figure><picture><source srcset="/files/lPpkM8sI339fQpNv57oj" media="(prefers-color-scheme: dark)"><img src="/files/WFeSAgHsH9Ry96Ukwmtn" alt=""></picture><figcaption></figcaption></figure>

{% hint style="info" %}

#### MITRE Auto-Population: What it Means

When a case is created, MITRE tactics and techniques may already be pre-populated. These come from the detection rules that fired to generate the incident. They reflect what the platform matched on, not necessarily the full scope of the attack.

Always review the pre-populated MITRE data. Add techniques your investigation reveals. Remove anything that turns out not to apply. The mapping should reflect you analytical conclusion, not just the intial detection signal.
{% endhint %}

<table><thead><tr><th width="175">Field</th><th width="177.5">Mandatory?</th><th>Notes</th></tr></thead><tbody><tr><td>Category</td><td>Yes, all cases</td><td>Must be set before resolution</td></tr><tr><td>Subcategory</td><td>Yes, all cases</td><td>Must be set before resolution</td></tr><tr><td>MITRE Tactics</td><td>Where applicable</td><td>Not required for config changes or false positives</td></tr><tr><td>MITRE Techniques</td><td>Where applicable</td><td>Refine and expand throughout, not a one-time action</td></tr></tbody></table>

## <mark style="color:$primary;">Step 6: Comments and Internal Notes: Continuous Documentation</mark>

Documentation is continuous, not retrospective. Add notes throughout the investigation. Use the Timeline tab to track all activity chronologically.

#### <mark style="color:$primary;">Internal Notes: Investigation and Workflow Records</mark>

Use Internal Notes for all investigation workings: findings, queries run, hypotheses tested, and workflow justifications. Internal notes are visible to users with access to the ticket case management system only and do not trigger notifications.

<figure><picture><source srcset="/files/jUEDbxAsyN3MrWMsJ2xt" media="(prefers-color-scheme: dark)"><img src="/files/qZgBNrdKC090yGMJElyQ" alt=""></picture><figcaption></figcaption></figure>

#### Comments: Notification Triggers

Use Comments when you need to communicate with stakeholders, to request action or provide an update. Comments appear in the incident page, trigger a notification to selected users, and automatically transition the case to Pending until there is a response. Write comments in plain language, as if explaining the situation to someone without a security background.

{% columns %}
{% column %}

<figure><picture><source srcset="/files/mMfB3LuFNgrrR6msLnHu" media="(prefers-color-scheme: dark)"><img src="/files/6yFmcaXiyo7YCmzFyi5C" alt=""></picture><figcaption></figcaption></figure>
{% endcolumn %}

{% column valign="middle" %}
{% hint style="info" %}

#### Status Automation: Pending

When you add a Comment, the case status automatically transitions: Processing to Pending.

When there is a response, the platform automatically transitions back to Processing. Do not manually change status to simulate this.

#### Design Rule

The timeline is the investigation. Internal notes and comments are the working record. The Description field is reserved for the final outcome summary. Do not use it for live investigation notes.
{% endhint %}
{% endcolumn %}
{% endcolumns %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.cybaops.com/modules/detect-and-respond-mdr/self-hosted-soc/phase-2-investigation-core-loop.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
