Tier-1 Fundamentals — Triage Discipline
- Alert anatomy: signal, context, escalation criteria
- Identity-context triage (M365, AD, Okta)
- Endpoint signal interpretation (EDR telemetry)
- Network signal interpretation (DNS, HTTP, TLS metadata)
- Tier-1 escalation discipline: when to call Tier-2