Team: Huntress Managed Endpoint Detection and Response (EDR), Huntress Managed Identity Threat Detection and Response (ITDR), Huntress Managed Security Information and Event Management (SIEM)
Product: Incident Reports
Environment: Huntress Dashboard
Summary: The Incident Report Timeline provides a chronological view of the events associated with an incident report, including relevant detection, investigation, response, remediation, and resolution activity. Eligible Managed EDR, Managed ITDR, and Managed SIEM incident reports can be exported as a PDF directly from the Timeline tab.
In this Article
Overview
Viewing the Timeline
Timeline Availability by Product
Exporting the Timeline as a PDF
Reading the Timeline
Timeline Events
Timeline FAQ
Overview
The Data Exfiltration Timeline offers a detailed, chronological view of the events surrounding an Incident Report. This includes the suspicious activities that triggered the report, as well as the specific actions Huntress took to remediate the threat. By reviewing the timeline, you can see the full sequence of the incident—from the initial compromise to the final resolution—helping you confirm the scope of the attack and verify that the threat has been neutralized.
Viewing the Timeline
You can access the timeline from an eligible incident report in the Huntress platform.
Log in to Huntress and go to the Incidents page.
Select View Report for the incident you want to review.
Select the Timeline tab.
Note: The Timeline tab is available only when the report has supported timeline data and uses a compatible report format. Older reports or reports without associated timeline data might not display the Timeline tab. A small number of incidents linked to multiple investigations are also not currently eligible for the Timeline or PDF export. This is a known limitation that Huntress is working to address.
Timeline Availability by Product
The timeline content varies by product:
Managed EDR: Shows the available SOC investigation timeline for the incident.
Managed ITDR: Shows the available incident timeline and identity-related investigation or response activity.
Managed SIEM: Shows the available SOC investigation timeline for the incident.
The exact events shown depend on the data available for the investigation. The timeline might include events such as signal activity, event-data receipt, analyst investigation, incident report creation, remediation activity, and incident report resolution.
Exporting the Timeline as a PDF
You can export an eligible incident report timeline as a PDF directly from the report.
Open the incident report.
Select the Timeline tab.
Select Export PDF in the top-right corner of the timeline.
The PDF contains the timeline content available for the report in a formatted, shareable document. You can use it to provide incident details to customers, leadership, auditors, or other stakeholders. If Export PDF is not visible, the report might not have supported timeline data, might use an older report format, or might not be eligible for export.
Reading the Timeline
The timeline is divided into a high-level Summary Dashboard and a detailed Event Feed.
Summary
The top section provides a snapshot of the incident's impact and resolution status.
- Milestones: Four cards track key moments in the incident lifecycle: Attack Start Time, Microsoft Logs Received (including any ingestion delay), Incident Report Sent, and Incident Report Resolved.
- Attack Overview: Displays the total Duration of the attack, the Compromised identity, and Threat actor actions such as Files Downloaded.
- Huntress Remediations: A breakdown of remediation actions categorized by status (Active, Assisted, and Manual).
-
Timeline Status: Located in the top right corner, the Last updated timestamp indicates the most recent data refresh. The timeline continues to populate with new details for approximately one hour after the initial report is sent. After that you will see a Final Update timestamp in the top right corner.
Event Feed
Below the summary, the event feed lists individual activities in chronological order.
- Sort & View: Use Sort By to toggle between "Newest to Oldest" or "Oldest to Newest". You can also use Collapse All to simplify the view.
- Relative Time: Next to each event header, a label indicates how much time has passed since the start of the attack (e.g., "30 seconds after Initial Access"). This helps you track the velocity of the attack without calculating the difference between timestamps manually.
- Event Details: Click the arrow on any event card to expand it to reveal specific details
Timeline Events
The timeline captures a mix of automated signals, Huntress analyst actions, and threat actor behaviors.
Incident Lifecycle & Response
These events track the progress of the incident from signal detection to resolution.
- Signal Event Occurred: Indicates when the malicious activity occurred that caused Huntress to generate the lead signal for the report.
- Huntress received event data: The time Huntress first ingested the data associated with the signal.
- Analyst Investigation: Marks when a Huntress analyst claimed the signal and began investigating.
- Huntress started an Incident Report: The time the report was created.
- Identity disabled: Logs when Huntress containment remediations are applied to an account.
- Manual remediation completed: Logs when a partner confirms a manual step, such as rotating credentials.
- Incident Report resolved: The final event marking the resolution of the report.
Threat Actor Activity
These events highlight specific actions taken by the threat actor during the session, which help identify other potential vulnerabilities or data exfiltration risks.
- Email Interactions: Tracks if the attacker accessed, copied, deleted, or moved emails within the victim's mailbox. Specific events include MailItemsAccessed, HardDelete, SoftDelete, and MoveToDeletedItems.
- Email Sending: Records if the attacker used the compromised account to send emails, including SendAs and SendOnBehalf actions.
- Mailbox Manipulation: Shows changes to mailbox or folder permissions, such as Add-MailboxPermission or UpdateCalendarDelegation.
- Inbox Rules: Flags the creation or modification of inbox rules (often used to hide malicious activity) via events like New-InboxRule and Set-InboxRule.
- File Interactions: Logs access, modification, copy, or deletion of files across SharePoint, OneDrive, and Teams. Events include FileAccessed, FileDeleted, FileModified, and FileRenamed.
- File Downloads: Specifically highlights when a threat actor has downloaded files from SharePoint or OneDrive (FileDownloaded).
- File Uploads: Tracks when files are uploaded to SharePoint or OneDrive (FileUploaded).
- Page & Site Interactions: Indicates when a threat actor viewed SharePoint site pages or performed search queries.
- Teams Messaging: Tracks interactions with Teams messages, including reading, sending, deleting, or editing messages (MessageRead, MessageSent, MessageDeleted).
-
Copilot Interactions: Flags interactions with Microsoft Copilot (CopilotInteraction).
Timeline FAQ
Why don’t I see a Timeline tab on my incident report?
The Timeline tab is available only for incident reports with supported investigation timeline data and a compatible report format. Timeline availability might vary by product and report. Older reports or reports without associated timeline data might not display the tab. A small number of incidents linked to multiple investigations do not currently support the timeline or PDF export; this is a known limitation that Huntress is working to address.
Which products support timeline PDF export?
Eligible incident reports for Managed EDR, Managed ITDR, and Managed SIEM can support PDF export of timelines. The Timeline tab and export control appear only when the report has the required timeline data.
How do I export an incident report timeline as a PDF?
Open the incident report, select the Timeline tab, and select Export PDF in the top-right corner. The exported PDF includes the timeline content available for that report.