Skip to content

Day 4

Incident investigation, threat hunting, playbooks and SOAR

Participants build a traceable incident case from several signals, test hypotheses, and write a human-controlled response playbook with a safe SOAR execution history.

Training case
D4-BALTNET-HUNT-001
Programme topics
6, 7
Assignments
P1 · P2 · P3 · P4 · ID-04

Where this day sits in the chain

Sequence: signal, triage, hypothesis, evidence, playbook, safe action.

Rule of the day

Endpoint isolation and account blocking are simulated only; human gates are mandatory.

Schedule

How the day runs

TimeTopicFormatOutput
09:00–09:45Cyber incident managementTheoryTriage decision model
10:00–12:00Incident investigation (triage and threat hunting)Practical P1 + P2Case and hypotheses
13:00–13:45Internal documents: playbooks and SOARTheoryPlaybook anatomy and safety gates
13:45–15:00Technical response playbooksPractical P3Response playbook
15:15–16:30Automated response with SOARPractical P4SOAR execution log
16:30–16:55Reflection on resultsReflectionDiscussion of decisions and evidence
17:00–19:00Independent workID-04Repeatable response playbook
Breaks: 09:45–10:00, 12:00–13:00 (lunch) and 15:00–15:15. Sessions run online.

Learning outcomes

By the end of the day, participants can

  1. D4.1Classify and prioritise a signal by impact, confidence, urgency, and asset and identity context.
  2. D4.2Build a traceable case timeline, tying every claim to a source and a specific field.
  3. D4.3Write a hunting hypothesis with expected behaviour, data, time window, and confirming and refuting conditions.
  4. D4.4Use ATT&CK T1078 and T1059.001 as investigative context, not as standalone proof of an incident.
  5. D4.5Tell a confirmed incident, a false positive and an insufficient-data case apart.
  6. D4.6Design a playbook with trigger, mandatory fields, roles, human gates, timeout, error path and rollback.
  7. D4.7Simulate SOAR actions safely and leave a complete history of decisions and evidence.

Practice

Practical assignments

Every stage has a duration, a deliverable artefact and an acceptance criterion. Work is done on template copies; original evidence is never modified.

  1. P1

    Triage and incident case

    Assess 12 signals by impact, confidence, urgency, and asset and identity context; every case claim tied to a source and field.
    Duration:
    60 min
    Deliverable:
    triage_sprendimai.csv + incidento_byla.md
  2. P2

    Threat hunting

    Three hypotheses with confirming and refuting conditions, tested across several data sources.
    Duration:
    60 min
    Deliverable:
    hunting_hipotezes.md
  3. P3

    Response playbook

    A versioned playbook: trigger, mandatory fields, roles, STOP and human gates, timeout, error path and rollback.
    Duration:
    75 min
    Deliverable:
    reagavimo_playbook.md
  4. P4

    SOAR simulation

    Two execution branches (approval timeout and missing owner) with a full history of decisions and evidence.
    Duration:
    75 min
    Deliverable:
    soar_vykdymo_zurnalas.csv

Extra labs

For deeper practice

The extra 90-minute or two-academic-hour labs are not automatically added to a full day; the instructor sets their schedule and submission time.

  • LAB 5D4-BALTNET-HUNT-002

    Hunting coverage and the limits of conclusions

    Extend the WS-23 behaviour hunt to six objects and separate a finding from insufficient visibility: “chain supported” is not “compromise confirmed”.

  • LAB 6D4-BALTNET-SOAR-003

    SOAR retries and state recovery

    Safe retries when a request is duplicated or its response is lost: operation keys, approval validity and a separately approved rollback.

Carry on in your environment

Related tools

  • SIEM.LT

    siem.lt

    Local-first threat intelligence workstation

    Check indicators found while hunting against MISP sources on the SIEM.LT workstation, and go back to the primary source.

    • MISP IOC and IP geography
    • OSINT / RSS radar in Lithuanian
    • IOC de-duplication and STIX 2.1 export
    • Docker deployment in minutes

Previous day

Day 3: SOC maturity, threat intelligence (CTI) and vulnerability management

Day 3

Next day

Day 5: Culture, exercises, system recovery and lessons learned

Day 5