Uncover: Pulling the evidence
Stage 2 · piece 4 of 7
What does the evidence say?
Uncover is where the investigation does its work. With Alert, Subject, and Scope established, this phase pulls Telemetry Collection and transmission of security-relevant data from remote sources for monitoring and analysis. , correlates it, identifies anomalies, and reconstructs the chain of activity from first action to last. The output is a coherent narrative supported by evidence.
What Uncover is for
Alert, Subject, and Scope told the analyst what fired, who was involved, and where the lines are. Uncover is where the analyst actually answers the question: what is going on, what did the adversary do, and what did they touch? Uncover ends with a narrative the analyst can defend.
The boundary with Subject is worth stating plainly: Subject was a quick contextual read built from what was already on screen; Uncover is the deep, multi-source evidence pull. The moment the analyst is opening new tools and running queries to answer a question, they are in Uncover.
What you will get from this chapter
Pull from the right data sources for the investigation: endpoint, network, identity, cloud, vulnerability, FIM, email, DLP, deception, and more.
Correlate evidence into one timeline: join keys, clock skew, confidence labels, the hypothesis ledger, and the rules that say when to stop digging.
Use threat intelligence appropriately: matching, attribution, TTP-driven hunting, and validating intel before acting on it.
Map findings to MITRE ATT&CK so the chain has a shared vocabulary the rest of the team can use.
Choose the right tools at the right step: SIEM, EDR, XDR, ITDR, network analysis, deception, forensics, sandboxes, vulnerability scanners, SOAR, CSPM, CDR, data lakes.
The five pillars
Data sources
The 17 telemetry sources an investigation may pull from. Knowing what each one captures (and does not) is the foundation.
Read →Correlation and the timeline
Join keys, clock skew, the running timeline, pivot discipline, stopping rules. The verb at the center of the phase.
Read →Threat intelligence
Indicator matching, attribution, TTP-driven hunting, tiers and validation. How to use intel without being used by it.
Read →MITRE ATT&CK
Tactics, techniques, procedures. The shared vocabulary for describing what an adversary did and how the chain progressed.
Read →Tool integration
SIEM, EDR, XDR, ITDR, deception, sandboxes, SOAR, CDR. The tools that make Uncover possible at scale.
Read →Why Uncover deserves its own phase
Endpoint A device that initiates network connections and runs user-facing software: laptop, desktop, server, phone, tablet. Endpoints are where most adversary tradecraft eventually shows up, which is why EDR exists. telemetry alone is rarely enough. Network logs alone are rarely enough. Uncover is the phase that brings sources together so the analyst can answer a question the way only correlated data can.
Mapping findings to MITRE ATT&CK A globally-accessible knowledge base of adversary tactics and techniques based on real-world observations, used for threat modeling and security operations. turns “the attacker did this and then this” into “T1566 → T1059.001 → T1071.” That precision matters at handoff, in trend analysis, and when describing the incident to a non-technical audience.
Threat Intelligence Evidence-based knowledge about existing or emerging threats, including context, mechanisms, indicators, implications, and actionable advice. is most useful as a hypothesis generator, not as ground truth. Uncover uses intel to guide what to look for, then validates with the evidence in the environment.
A common Uncover failure mode is starting with a tool (“let me run a SIEM query”) instead of starting with a question. The methodology asks what the analyst needs to know, then chooses the tool that can answer it.
Key Takeaway
Uncover is the longest phase of most investigations, and the one where preparation pays off most. Strong Alert, Subject, and Scope work means Uncover is structured. Weak earlier phases mean Uncover wanders.
Next up
Data sources
The 17 telemetry sources an Uncover investigation pulls from, and what each one is good for.
Read data sources