Analysis is the work of turning collected telemetry into meaningful signals. It applies correlation and detection logic across many events to surface patterns that indicate adversary behavior, distinguishing genuine activity from the large volume of benign noise that normal operations generate.
Within the Detection phase, analysis sits between raw collection and the alerts that reach responders. Individual log lines rarely tell a complete story, so analysis joins events across time, hosts, and identities to reveal sequences that matter: a suspicious login followed by unusual process execution, or data movement that departs from an established baseline.
In practice, analysis combines rule-based matching, statistical baselining, and behavioral analytics. Defenders write and refine detection logic that maps to known techniques, tune thresholds to reduce false positives, and enrich events with context such as asset criticality and threat intelligence. The goal is reliable, explainable signals that an analyst can act on with confidence, rather than a flood of low-quality matches. Analysis improves as defenders learn which patterns prove meaningful and which do not.
References#
- NIST SP 800-61, Computer Security Incident Handling Guide
- MITRE ATT&CK, Detections and Analytics