When working with alerts, the first thing you do is to confirm that the alert is valid by looking at the PCAP for that particular session.
After the alert is validated, you need to determine three things:
Was the host actually compromised?
What was affected in the environment? For example, has the attacker moved laterally or tried to attack other hosts?
Is there a backdoor installed on an infected host?
To answer these questions, you need to view the details of the alert and then construct queries around the alert. This chapter explains how to view alerts, add alerts to queries, and filter alerts.