Scoping with a SIEM
In this hands-on lab, you will learn the basics of scoping an incident, including the data, data sources, and common techniques used for scoping. You will practice incident scoping in the Elastic SIEM using common search criteria.

Course Content
Upon completion of this lab, you should be able to:
- Explain the purpose of scoping within incident response.
- Describe the data, data sources, and generic techniques we use for scoping.
- Understand the pros/cons of scoping using a SIEM versus other data sources.
- Conduct incident scoping in Elastic using common search criteria.













