| name | security-investigation-timeline |
| description | Build a defensible security investigation timeline across authentication, process, network, data, configuration, and administrative events to determine initial access, persistence, movement, actions, and scope. |
Security Investigation Timeline
Use when this procedure is the primary professional method needed for the assignment.
Procedure
- Confirm the decision or outcome this work must support, its scope, owner, constraints, and definition of success.
- Establish the evidence baseline using security logs, application/infra telemetry, IAM, EDR/process/network evidence, deploy/config history, and user reports. Do not fill material gaps with assumptions when they can change the result.
- Normalize timestamps/identities, correlate events by actor/resource/session, separate evidence from hypothesis, identify gaps, test alternate narratives, and preserve provenance.
- Exercise realistic edge, failure, transition, or exception cases that could invalidate the result; record unresolved uncertainty explicitly.
- Validate the output against the original outcome and any neighboring professional contracts so this skill does not silently absorb another specialist's authority.
- Record the resulting artifact, measurements, decisions, provenance, and handoff information needed for another owner to reproduce or continue the work.
Quality gate
The timeline clearly marks confirmed, inferred, and unknown events and supports scope/remediation decisions.