ArcanaIncident-response documentationBrowse the feedTemplates
Back to feed
Runbook · Analysis
RB-ANALYSIS-026

User Activity Validation

1. Prerequisites

Before starting this runbook, ensure the following:

  • Access to EDR telemetry
  • Access to SIEM telemetry
  • User identity confirmed
  • Endpoint hostname identified
  • Relevant alerts collected
  • Incident ticket created

2. Step-by-Step Instructions

  1. Identify User Context

    Collect:

    • Username
    • Department
    • Manager
    • Privilege level
    • Endpoint ownership
    • Normal job responsibilities

    Determine:

    • Whether the user is technical or non-technical
    • Whether elevated privileges exist
    • Whether administrative activity is expected
  2. Review Alerted Activity

    Identify:

    • Process execution activity
    • Command-line activity
    • Script execution
    • Network activity
    • Authentication activity
    • File access activity

    Determine:

    • What actions triggered the alert
    • When activity occurred
    • Which systems were involved
  3. Review Historical User Behaviour

    Assess:

    • Normal login patterns
    • Normal working hours
    • Normal application usage
    • Administrative tooling usage
    • Historical alerts

    Identify deviations from established behaviour.

  4. Validate Business Purpose

    Determine whether activity aligns with:

    • Approved change requests
    • Software deployment activities
    • Administrative operations
    • Security testing activities
    • Development activities
    • Scheduled maintenance

    Review available documentation.

  5. Validate with Relevant Stakeholders

    Where required:

    • Contact user
    • Contact manager
    • Contact system owner
    • Contact IT operations team
    • Contact development team

    Confirm:

    • Whether activity was expected
    • Whether activity was authorised
    • Whether activity was approved

    Document all responses.

  6. Review Related Activity

    Assess:

    • Authentication activity
    • Endpoint activity
    • Network activity
    • Cloud activity
    • File access activity

    Determine whether activity was isolated or part of broader behaviour.

  7. Assess Risk

    Determine whether activity is:

    • Authorised and expected
    • Authorised but risky
    • Unauthorised but benign
    • Suspicious
    • Malicious

    Document justification.

  8. Identify Additional Indicators

    Review for:

    • Persistence mechanisms
    • Credential access
    • Data staging
    • Data exfiltration
    • Privilege escalation
    • Lateral movement

    If identified, expand investigation scope.

  9. Escalate if Required

    If evidence supports another incident type:

    Activate:

    • PB-003 Endpoint Malware
    • PB-004 Account Takeover
    • PB-005 Data Exfiltration
    • PB-006 Insider Threat
    • PB-007 Cloud Compromise
    • PB-009 Privilege Escalation
    • PB-010 Lateral Movement

    Continue executing current playbook concurrently.

  10. Update Incident Record

    Record:

    • User validation findings
    • Stakeholder responses
    • Behaviour assessment
    • Risk assessment
    • Escalation decisions

    Attach supporting evidence.

3. Post-Action

Upon completion:

  • Ensure all stakeholder responses are documented
  • Ensure activity legitimacy determination is recorded
  • Ensure escalation decisions are documented
  • Ensure supporting evidence is attached
  • Ensure incident ticket is updated

Contributor

Vishal Thakur GitHub: https://github.com/malienist

Contributed to the Arcana Incident Response Documentation Framework.