> For the complete documentation index, see [llms.txt](https://darkcybe.gitbook.io/holocron/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://darkcybe.gitbook.io/holocron/investigate/investigate.md).

# Incident Response & DFIR

Incident response and DFIR organised around questions, artifacts and defensible conclusions.

`INVESTIGATE // RECONSTRUCT THE EVENT`

An investigation needs an account of what happened and a visible route back to the evidence. This section is for incident response, forensic workflows, timelines and threat investigation: the work of testing an explanation against the artifacts available.

## Frame the investigation

Begin with a bounded question: which account acted, what executed, or how two events relate. Record the time window, systems in scope and gaps in collection before expanding the narrative.

Keep three things distinct in the working account:

* **Observation:** what the artifact actually contains, with its provenance.
* **Interpretation:** what that observation supports and which assumptions it needs.
* **Open question:** what would strengthen, contradict or change the interpretation.

That separation is the editorial standard for investigations here. Timelines should preserve source timestamps and explain any normalisation; reports should make competing explanations visible.

## Follow the work

Use [Reference](/holocron/reference/reference.md) for artifact fields and interpretation boundaries. Move to [Detect](/holocron/detect/detect.md) when the investigation produces a behaviour worth looking for elsewhere. Use [Build](/holocron/build/build.md) when a disputed assumption needs an isolated experiment.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://darkcybe.gitbook.io/holocron/investigate/investigate.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
