BeeraSafe

Quickstart: your first investigation

From sign-in to a reviewable result in six steps.

Last updated · September 2026

On this page

The fastest route to a useful result is a narrow question with a clear scope and enough evidence to distinguish facts from assumptions.

  1. Choose the operating mode

    Select Defensive analysis for telemetry, alerts, incidents, detections, vulnerabilities, or remediation. Select Authorized test for owned assets, approved labs, and explicitly authorized assessment planning.

  2. Name the case

    Use an incident number, engagement identifier, change number, or another reference that a teammate can recognize later.

  3. Select the assets

    Use the mode-specific asset library to constrain the question. Add only relevant sources or targets; do not use a broad label when a narrower one is available.

  4. Attach evidence

    Paste or upload the relevant excerpt. Remove secrets and unrelated personal data. Include timestamps, timezone, source, and collection limitations when available.

  5. Ask an operator question

    Request a bounded deliverable: a triage decision, timeline, hypothesis table, detection rule review, remediation plan, or safe validation plan.

  6. Review and record

    Check the output against the evidence, mark uncertainty, assign an owner, and preserve the result in your case-management process.

A strong first prompt
“Triage this EDR alert from the attached process tree. Separate observed facts from hypotheses, identify the most likely execution chain, list missing telemetry, and recommend three reversible containment actions. Do not assume the host is compromised without evidence.”
Was this page helpful?