How it actually works

An investigation is six things you do. None of them are automated.

Review evidence, form a hypothesis, write your notes, build the timeline, call your verdict — then get scored on all of it, not just whether the answer matches.

Evidence review

Work the alert timeline across identity, endpoint, email, and cloud. Pin what matters — nothing is pre-selected for you.

Hypotheses

Form a theory of what happened, then look for evidence that would prove it wrong. Decoys are seeded on purpose.

Notes

Write your reasoning as you go. Your case notes are what gets graded, alongside your evidence.

Timeline

Assemble the events you've pinned into an ordered narrative — the story of the incident, in your words.

Findings & verdict

Call it: true positive, false positive, or benign. State the required response actions for the case.

Scoring

Graded against a hidden ground truth — see the full rubric.

Evidence review

Your Personal Workspace

clickbox.io / investigations / INC-42188
INC-42188
Consent phish → privileged data access
active
opened 4h ago
21:58
OAuth consent phish delivered
Email
Sender ASN first-seen 6h ago · no DMARC alignment
22:04
Consent granted to 'Contoso Reports'
Email
Scopes: Mail.Read, offline_access
22:11
Refresh token minted
Identity
Client 4a1e… · IP 45.86.x.x (unfamiliar ASN)
01:47
MFA fatigue — 14 pushes, 1 approval
Identity
sarah.chen@contoso.com
02:14
SSH to SRV-DB-07 accepted
Endpoint
Key auth · session 44m
02:19
LSASS memory read
Endpoint
procdump-like behaviour, unsigned binary
02:41
3 privileged queries on customers.pii
Cloud
1.2M rows scanned · no export
02:58
S3 policy widened on prod-artifacts
Cloud
Principal: * (blocked by ThreatLens playbook)
Evidence you've pinned
OAuth consent phish deliveredT1566.002
Refresh token minted from unfamiliar ASNT1078
MFA fatigue — 14 pushes, 1 approvalT1621
SSH to SRV-DB-07 acceptedT1021.004
LSASS memory readT1003.001
Your case notes (example)

A consent-phish granted persistent mail access, which was used to socially engineer an MFA approval and pivot to SRV-DB-07. Credential material was read from memory before privileged queries hit customers.pii. No exfiltration observed — my verdict below.

Revoke tokenQuarantine SRV-DB-07Export brief