skip to content

What must a tier-1 escalation to tier-2 carry besides the alert identifier?

level: middleimportance: should knowfreq 58%

answer

  1. transfer reasoning, not a ticket link
  2. clean results are results too
  3. say what you did not check
  4. actions change the estate
  5. three clocks: activity, detection, pickup

basics

~20 s

A stated hypothesis, every lookup already run and what each returned including the negative results, what was deliberately not checked, any action already taken on the estate, and the exact identifiers and time window. Tier-2 inherits an investigation, not a ticket.

solid answer

~50 s

The escalation is a handover of an open investigation about a possibly live adversary, so it has to transfer reasoning rather than a pointer. I would state the hypothesis in one sentence — what I think is happening and to whom — then list every lookup I ran with its result, including the ones that came back clean, because a negative result tells the next analyst which explanation is already excluded and stops them repeating my work. I state explicitly what I did not check and why, so nothing unexamined is mistaken for examined. Then the actions: whether I isolated a host, disabled an account or revoked a session, and when, because those change the estate and may already have told the intruder they are seen. Finally the identifiers and the three clocks that matter: when the activity happened, when the detection fired, and how long it sat in the queue.

go deeper

for a junior

Be ready to list what you would put in an escalation: your hypothesis, the lookups you ran and their results, what you could not check, and anything you already did to the host or account.

for a middle

Explain why negative results and already-taken actions are the two things that most change the next analyst's reading, and why activity time, detection time and pickup time are three different clocks.

for a senior

Show how you make omissions visible rather than trusting memory — a template with an explicit 'not checked' field — and how you stop overstated verdicts propagating as fact.

for a principal

Own the fact that every tier boundary buys throughput by paying context at each handover, and be able to say what your escalation format is doing to buy that context back.

## Why this is not a pager handoff Handing a pager over at the end of a shift transfers *responsibility for a service*. Escalating an alert transfers *a hypothesis about an adversary who may still be active*, and the two need completely different content. The incoming analyst is not being asked "is it up?" — they are being asked to continue somebody else's reasoning without repeating it and without inheriting its mistakes silently. That is why an escalation of "see alert 44812, looks suspicious, please review" is worse than useless: it costs tier-2 the whole investigation again, and it conceals the two things only tier-1 knows. ## The six things that must travel **1. The hypothesis, in one sentence.** "I think this account's credentials are being used by someone other than its owner, from HR-LAPTOP-14, starting around 02:40." A hypothesis is falsifiable and gives the next analyst something to attack. "Suspicious activity" is not a hypothesis. Crucially, the hypothesis is offered as a claim to be tested, not as a conclusion — tier-2's job includes deciding it is wrong. **2. What was checked, and what it returned — including the clean results.** This is the part juniors leave out and the part that saves the most time. "Parent process was `explorer.exe`" and "the account has signed in from this device on 40 previous days" are findings even though they point away from malice. Without them tier-2 re-runs the same queries; worse, tier-2 may assume a check was never done and treat an already-excluded explanation as open. **3. What was deliberately not checked, and why.** "I did not pull the process tree because the host has been offline since 03:10." This is the difference between an unexamined gap and an unexaminable one, and it is where the case's real uncertainty lives. **4. Actions already taken on the estate, with timestamps.** Did you isolate the host, disable the account, kill a session, block a destination, ask the user a question? Every one of these changes the environment and some of them are visible to an adversary. If tier-2 does not know a host was isolated at 03:12, they will read the silence after that as "the activity stopped" — a completely wrong inference. Asking the account owner "did you run this?" is itself an estate-changing action if the account is compromised: you may have just told the intruder. **5. Identifiers and scope.** Hostnames, account names, source addresses, process names and hashes, the specific detection that fired, and the exact time window searched — with its timezone. "I looked at the last 24 hours" and "I looked at 02:00–04:00 UTC" support very different conclusions about what the absence of further activity means. **6. The clocks.** When the activity occurred, when the detection fired, and when the case was picked up. The gap between the first two is a telemetry and detection-latency fact; the gap between the last two is a SOC capacity fact. Both change how tier-2 prioritises: an alert about activity from six hours ago is a different problem from one about activity still in progress. ## What good looks like in practice Most SOCs enforce this with a template in the case system rather than trusting memory, and the template's job is to make the *omissions* visible — a blank "not checked" field is an obvious defect in review, whereas a missing paragraph in free text is invisible. Some teams add one more field that is worth arguing for: **what would change my mind**. Naming the single piece of evidence that would flip the verdict turns the escalation into a work instruction, and it is the fastest way for tier-2 to spend their first five minutes well. ## The failure modes an interviewer is probing for - **Conclusion laundering.** Tier-1 writes "confirmed malicious" when they mean "I could not explain it". Tier-2 then treats a guess as an established fact and builds on it. Escalations should state confidence, and the honest phrase is "unexplained", not "confirmed". - **Silent containment.** An action taken and not recorded corrupts every later inference about what the adversary did or stopped doing. - **The negative-result gap.** Unrecorded clean checks are the single largest source of duplicated work in triage. - **Timezone drift.** A timeline assembled from records in three timezones with no normalisation is the most common way a case's narrative comes out wrong. Say all of that and you have shown the interviewer that you understand an escalation as a transfer of *understanding under time pressure*, which is what the tier boundary actually costs you and what a good handover buys back.

  • Why does an escalation have to record actions the tier-1 analyst already took?
    Because they changed the environment the next analyst is reading. If a host was isolated at 03:12 and tier-2 does not know, they will read the quiet afterwards as the activity having stopped on its own. Some actions are also visible to an adversary — isolating a host, resetting a password, or asking the account owner whether they ran a command can all tell an intruder they have been seen.
  • How should a tier-1 analyst express confidence in an escalation?
    In plain words tied to evidence: 'unexplained', 'consistent with X but I could not exclude Y', 'confirmed by Z'. The failure is conclusion laundering — writing 'confirmed malicious' when the truth is 'I could not explain it'. Tier-2 will build on whatever wording they are given, so an overstated verdict propagates as an established fact and quietly removes the alternatives from consideration.
  • Is it useful to write down what would change your mind about the case?
    Yes, and it is the highest-value optional field. Naming the single artefact that would flip the verdict — the parent process, the sign-in history for the hour before, the change record for that window — turns a description into a work instruction and directs the next analyst's first five minutes. It also exposes cases where nothing available could settle the question, which is itself a finding.

saying these in an interview costs you the question

  • Escalates with only an alert link and 'looks suspicious'
  • Records only findings that support the hypothesis
  • Omits containment actions already taken on the host
  • Writes 'confirmed malicious' meaning 'I cannot explain it'
  • Leaves the searched time window and timezone unstated
  • Treats an unchecked item as if it had been checked and was clean

context