Scope: Defining investigation boundaries

Stage 1 · piece 3 of 7

Where are the lines?

On-shift target 5–12 min Operational target for triaging a live alert, not a reading-time estimate. Complex cases legitimately exceed it.

Scope decides what is in the investigation and what is out. Without it, investigations sprawl indefinitely. With it, every minute of analyst time is directed at material questions.

What Scope is for

Subject produced a map of identities and relationships. Scope takes that map and draws the formal boundary: which entities are in this investigation, which time windows apply to each, which regulations constrain the work, and which Infrastructure The systems, networks, and services that computing runs on. In triage the word points two directions: the organization's infrastructure is what alerts fire on, and attacker infrastructure is the set of C2 servers, domains, and staging hosts an adversary operates, which pivoting on indicators is meant to map. paths get walked. Without scope, Uncover has no idea where to look.


What you will get from this chapter

⚖️

Recognize which regulatory frameworks attach, GDPR, CCPA, PCI DSS, HIPAA, SOX, SEC disclosure, and start the right clocks at the right moment.

🕐

Set defensible time windows for historical review and real-time investigation, calibrated to the threat type.

🧭

Decide which entities are in scope and how to handle access modeling, dependency tracing, and relationship mapping.

🏗️

Recognize the infrastructure boundaries that constrain what an investigation can actually see.


The four boundary types


Why Scope is its own phase

Analysts who skip Scope often follow every interesting thread they find. Each thread feels productive in the moment. By the end of the shift, three threads are open, none are resolved, and the alert that started it all is still triaging itself.

Investigating an account that touched HIPAA-bound data carries different obligations than investigating a developer’s sandbox. Scope is where those obligations are recognized and formalized, before Uncover starts touching data that has rules attached.

A typical alert is investigated against the last 24 hours. A slow-burn insider case may need 6 months. The window is a choice about the threat, not a SIEM default.

Scope is also honest about what the SOC cannot see. Air-gapped systems, third-party SaaS without logging access, off-network mobile devices. Naming the gaps upfront is what keeps Uncover from spending time on impossible queries.


Key Takeaway

Scope is the phase that says “this and not that.” Four boundary types, regulatory, time, entity, infrastructure, and one page of output: the clocks, windows, entities, and visibility limits that every later phase works within.

Next up

Regulatory boundaries

GDPR, CCPA, PCI DSS, HIPAA, SOX, SEC disclosure. The rules that shape investigation.

Read regulatory