Uncover: Pulling the evidence

Stage 2 · piece 4 of 7

What does the evidence say?

On-shift target 20–45 min Operational target for triaging a live alert, not a reading-time estimate. Complex cases legitimately exceed it.

Uncover is where the investigation does its work. With Alert, Subject, and Scope established, this phase pulls Telemetry Collection and transmission of security-relevant data from remote sources for monitoring and analysis. , correlates it, identifies anomalies, and reconstructs the chain of activity from first action to last. The output is a coherent narrative supported by evidence.

What Uncover is for

Alert, Subject, and Scope told the analyst what fired, who was involved, and where the lines are. Uncover is where the analyst actually answers the question: what is going on, what did the adversary do, and what did they touch? Uncover ends with a narrative the analyst can defend.

The boundary with Subject is worth stating plainly: Subject was a quick contextual read built from what was already on screen; Uncover is the deep, multi-source evidence pull. The moment the analyst is opening new tools and running queries to answer a question, they are in Uncover.


What you will get from this chapter

📥

Pull from the right data sources for the investigation: endpoint, network, identity, cloud, vulnerability, FIM, email, DLP, deception, and more.

🔗

Correlate evidence into one timeline: join keys, clock skew, confidence labels, the hypothesis ledger, and the rules that say when to stop digging.

🌐

Use threat intelligence appropriately: matching, attribution, TTP-driven hunting, and validating intel before acting on it.

🎯

Map findings to MITRE ATT&CK so the chain has a shared vocabulary the rest of the team can use.

🛠️

Choose the right tools at the right step: SIEM, EDR, XDR, ITDR, network analysis, deception, forensics, sandboxes, vulnerability scanners, SOAR, CSPM, CDR, data lakes.


The five pillars


Why Uncover deserves its own phase

Endpoint A device that initiates network connections and runs user-facing software: laptop, desktop, server, phone, tablet. Endpoints are where most adversary tradecraft eventually shows up, which is why EDR exists. telemetry alone is rarely enough. Network logs alone are rarely enough. Uncover is the phase that brings sources together so the analyst can answer a question the way only correlated data can.

Mapping findings to MITRE ATT&CK A globally-accessible knowledge base of adversary tactics and techniques based on real-world observations, used for threat modeling and security operations. turns “the attacker did this and then this” into “T1566 → T1059.001 → T1071.” That precision matters at handoff, in trend analysis, and when describing the incident to a non-technical audience.

Threat Intelligence Evidence-based knowledge about existing or emerging threats, including context, mechanisms, indicators, implications, and actionable advice. is most useful as a hypothesis generator, not as ground truth. Uncover uses intel to guide what to look for, then validates with the evidence in the environment.

A common Uncover failure mode is starting with a tool (“let me run a SIEM query”) instead of starting with a question. The methodology asks what the analyst needs to know, then chooses the tool that can answer it.


Key Takeaway

Uncover is the longest phase of most investigations, and the one where preparation pays off most. Strong Alert, Subject, and Scope work means Uncover is structured. Weak earlier phases mean Uncover wanders.

Next up

Data sources

The 17 telemetry sources an Uncover investigation pulls from, and what each one is good for.

Read data sources