Investigate suspected compromise, preserve incident evidence, build a timeline and plan containment, recovery and verification. Use for incident response, account takeover, suspicious host activity or recovery after an attack.