---
title: "SOC: collaborate on a simulated alert"
description: Use fictional logs to practice analysis, review, and response recommendations.
lastVerified: 2026-09-23
---

# 4.3 SOC: collaborate on a simulated alert

This example uses **fictional materials** and does not require a connection to an external business system. The goal is to leave a clear record of responsibilities and results that you can check. It does not guarantee that the model's judgments are correct.

## Prepare

Connect a model. Create analysis, investigation, and review colleagues in the same business area or in General work, then add them to the same group. Each colleague only needs the materials for this exercise. Without authorization for external tools, do not assume it can search or write to an external system.

## Sample materials

```text
Simulated alert: host DEMO-01 had 12 failed logins at 09:20, followed by one successful login at 09:23. Source address: 192.0.2.20. No information is available about asset criticality, the user's work schedule, or subsequent activity.
```

## 1. Define the first round of work

Share the materials in the group and mention the first colleague:

```text
List facts in time order, distinguishing unusual activity from a conclusion that an intrusion occurred. Keep the supporting evidence from the materials for each item. If information is missing, list questions instead of guessing.
Do not isolate hosts, block accounts, or perform any real response actions.
```

If you need formal tracking, create a linked task and check its owner and scope. Then review whether the resulting facts are complete.

## 2. Hand over and review

After checking the first result, pass the confirmed content to the second colleague:

```text
List the additional evidence needed and read-only investigation steps. Use only confirmed materials and label inferences separately.
```

Then pass it to the review colleague:

```text
Check the evidence for every conclusion and provide recommendations that need human judgment. Go beyond polishing the writing: identify where the source and conclusion do not agree.
```

## 3. Verify the results

Expected deliverables include a fact list, a working draft, and review comments. Check the owner, sources, unresolved questions, and task records for each deliverable.

Do not isolate hosts, block accounts, or perform any real response actions. If you later connect real tools, separately verify their scope, credentials, and approval requirements. This exercise grants no permission for real external actions.

## Reuse the workflow

Save stable input and output requirements as a task template. Configure an automation only after the recurring input source and acceptance criteria are clear. Keep the handoffs manual for the first exercise so that unverified steps do not run automatically in sequence.
