Day 4
Incident investigation, threat hunting, playbooks and SOAR
Participants build a traceable incident case from several signals, test hypotheses, and write a human-controlled response playbook with a safe SOAR execution history.
- Training case
- D4-BALTNET-HUNT-001
- Programme topics
- 6, 7
- Assignments
- P1 · P2 · P3 · P4 · ID-04
Where this day sits in the chain
Sequence: signal, triage, hypothesis, evidence, playbook, safe action.
Rule of the day
Endpoint isolation and account blocking are simulated only; human gates are mandatory.
Schedule
How the day runs
| Time | Topic | Format | Output |
|---|---|---|---|
| 09:00–09:45 | Cyber incident management | Theory | Triage decision model |
| 10:00–12:00 | Incident investigation (triage and threat hunting) | Practical P1 + P2 | Case and hypotheses |
| 13:00–13:45 | Internal documents: playbooks and SOAR | Theory | Playbook anatomy and safety gates |
| 13:45–15:00 | Technical response playbooks | Practical P3 | Response playbook |
| 15:15–16:30 | Automated response with SOAR | Practical P4 | SOAR execution log |
| 16:30–16:55 | Reflection on results | Reflection | Discussion of decisions and evidence |
| 17:00–19:00 | Independent work | ID-04 | Repeatable response playbook |
Learning outcomes
By the end of the day, participants can
- D4.1Classify and prioritise a signal by impact, confidence, urgency, and asset and identity context.
- D4.2Build a traceable case timeline, tying every claim to a source and a specific field.
- D4.3Write a hunting hypothesis with expected behaviour, data, time window, and confirming and refuting conditions.
- D4.4Use ATT&CK T1078 and T1059.001 as investigative context, not as standalone proof of an incident.
- D4.5Tell a confirmed incident, a false positive and an insufficient-data case apart.
- D4.6Design a playbook with trigger, mandatory fields, roles, human gates, timeout, error path and rollback.
- D4.7Simulate SOAR actions safely and leave a complete history of decisions and evidence.
Practice
Practical assignments
Every stage has a duration, a deliverable artefact and an acceptance criterion. Work is done on template copies; original evidence is never modified.
- P1
Triage and incident case
Assess 12 signals by impact, confidence, urgency, and asset and identity context; every case claim tied to a source and field.- Duration:
- 60 min
- Deliverable:
- triage_sprendimai.csv + incidento_byla.md
- P2
Threat hunting
Three hypotheses with confirming and refuting conditions, tested across several data sources.- Duration:
- 60 min
- Deliverable:
- hunting_hipotezes.md
- P3
Response playbook
A versioned playbook: trigger, mandatory fields, roles, STOP and human gates, timeout, error path and rollback.- Duration:
- 75 min
- Deliverable:
- reagavimo_playbook.md
- P4
SOAR simulation
Two execution branches (approval timeout and missing owner) with a full history of decisions and evidence.- Duration:
- 75 min
- Deliverable:
- soar_vykdymo_zurnalas.csv
Extra labs
For deeper practice
The extra 90-minute or two-academic-hour labs are not automatically added to a full day; the instructor sets their schedule and submission time.
LAB 5D4-BALTNET-HUNT-002
Hunting coverage and the limits of conclusions
Extend the WS-23 behaviour hunt to six objects and separate a finding from insufficient visibility: “chain supported” is not “compromise confirmed”.
LAB 6D4-BALTNET-SOAR-003
SOAR retries and state recovery
Safe retries when a request is duplicated or its response is lost: operation keys, approval validity and a separately approved rollback.
Carry on in your environment
Related tools
SIEM.LT
siem.ltLocal-first threat intelligence workstation
Check indicators found while hunting against MISP sources on the SIEM.LT workstation, and go back to the primary source.
- MISP IOC and IP geography
- OSINT / RSS radar in Lithuanian
- IOC de-duplication and STIX 2.1 export
- Docker deployment in minutes