Fill in the blanks on the left. The worked example on the right shows the standard a Tier 2 reviewer expects.
Two or three sentences: what happened, to whom, and what you concluded.
Worked example
At 13:04Z j.rivera (Finance) reported a phishing email from a look-alike domain. Proxy logs confirm credentials were submitted to a domain registered two days earlier. Assessed as a confirmed credential-phishing compromise; escalated to Tier 2.
One line per event, in UTC, oldest first.
Worked example
12:58Z Spoofed mail delivered (SPF/DKIM/DMARC fail)
13:01Z User clicked rewritten URL
13:02Z HTTP POST of credentials (412 bytes)
13:04Z User self-reported via Report Phishing
Confirmed header authentication failures; ran WHOIS and IP reputation; verified POST in proxy logs; requested session revocation and password reset; blocked both domains; searched mail store for other recipients.
What should happen next, and who owns it.
Worked example
Tier 2 to hunt for logins to j.rivera from unfamiliar IPs. Add both domains to the block list permanently. Consider phishing-resistant MFA for Finance.
Preview
# Incident report — A-1041 Credential phishing email reported by user — link clicked
## Summary
_Not completed_
## Timeline
_Not completed_
## Affected assets
_Not completed_
## Indicators of compromise
_Not completed_
## Actions taken
_Not completed_
## Recommendation
_Not completed_