Scope: Defining investigation boundaries
Stage 1 · piece 3 of 7
Where are the lines?
Scope decides what is in the investigation and what is out. Without it, investigations sprawl indefinitely. With it, every minute of analyst time is directed at material questions.
What Scope is for
Subject produced a map of identities and relationships. Scope takes that map and draws the formal boundary: which entities are in this investigation, which time windows apply to each, which regulations constrain the work, and which Infrastructure The systems, networks, and services that computing runs on. In triage the word points two directions: the organization's infrastructure is what alerts fire on, and attacker infrastructure is the set of C2 servers, domains, and staging hosts an adversary operates, which pivoting on indicators is meant to map. paths get walked. Without scope, Uncover has no idea where to look.
What you will get from this chapter
Recognize which regulatory frameworks attach, GDPR, CCPA, PCI DSS, HIPAA, SOX, SEC disclosure, and start the right clocks at the right moment.
Set defensible time windows for historical review and real-time investigation, calibrated to the threat type.
Decide which entities are in scope and how to handle access modeling, dependency tracing, and relationship mapping.
Recognize the infrastructure boundaries that constrain what an investigation can actually see.
The four boundary types
Regulatory boundaries
GDPR, CCPA, PCI DSS, HIPAA, SOX, SEC disclosure. The clocks, preservation duties, and owners that attach to regulated data.
Read →Time boundaries
Historical review windows, real-time investigation, retention limits. When the investigation starts and stops.
Read →Entity boundaries
Primary and secondary entities, relationship mapping, access modeling, dependency tracing. Which subjects are in.
Read →Infrastructure boundaries
What the SOC actually has visibility into. Network segments, cloud accounts, geographic regions, retention.
Read →Why Scope is its own phase
Analysts who skip Scope often follow every interesting thread they find. Each thread feels productive in the moment. By the end of the shift, three threads are open, none are resolved, and the alert that started it all is still triaging itself.
Investigating an account that touched HIPAA-bound data carries different obligations than investigating a developer’s sandbox. Scope is where those obligations are recognized and formalized, before Uncover starts touching data that has rules attached.
A typical alert is investigated against the last 24 hours. A slow-burn insider case may need 6 months. The window is a choice about the threat, not a SIEM default.
Scope is also honest about what the SOC cannot see. Air-gapped systems, third-party SaaS without logging access, off-network mobile devices. Naming the gaps upfront is what keeps Uncover from spending time on impossible queries.
Key Takeaway
Scope is the phase that says “this and not that.” Four boundary types, regulatory, time, entity, infrastructure, and one page of output: the clocks, windows, entities, and visibility limits that every later phase works within.
Next up
Regulatory boundaries
GDPR, CCPA, PCI DSS, HIPAA, SOX, SEC disclosure. The rules that shape investigation.
Read regulatory