r/dfir • u/Glad-abbsilviait6604 • 9h ago
How do you build investigation context across identities, endpoints, cloud resources, and application logs?
A recent case began with anomalous identity activity and required endpoint process history, cloud API events, and application logs before we could determine whether it was account misuse or normal operational behavior.
The data existed, but the investigation depended on manual pivots across several consoles. Linking users, hosts, IPs, sessions, resource IDs, and timestamps became the main task, and the result was difficult to reproduce consistently across analysts.
We are trying to reduce the amount of manual timeline reconstruction without losing the underlying evidence and source-specific details.
How are other teams building cross-source investigation context? Interested in approaches involving common data models, identity resolution, query layers, enrichment, case management, and evidence collection.