**Scenario:** A correlation search fires for "Excessive Failed Logins" targeting user `jdoe`. 15 minutes later, a second correlation search fires for "Successful Login After Multiple Failures" for the same user from an IP geolocated in a foreign country.
As the SOC analyst, you must: 1) Open Incident Review 2) Correlate the two notable events 3) Check the Asset & Identity framework for jdoe's role 4) Determine if the IP is on any threat intelligence list 5) Execute an Adaptive Response action.