1. Scope and authorization
State the lab you own or are allowed to use, the fictional scenario and the activity you performed. Exclude public targets and live company records unless permission and safe handling are established. Never publish credentials.
2. Data and environment
Describe the event fields, lab topology, tools, versions and synthetic-data method. Include enough setup detail to repeat the exercise without copying private logs or identifiers.
3. Question and method
State the investigation question and the sequence you followed. Distinguish a detection pattern from a confirmed incident. Explain why the selected events matter and what other explanations could fit.
4. Validation
Show expected and observed results for both suspicious and ordinary activity. Include false positives, missing fields and cases your rule cannot decide. A rule firing once does not establish operational reliability.
5. Findings and risk
Separate observations, hypotheses and confirmed conclusions. Explain the potential consequence in plain words. Recommend proportionate next checks or controls rather than treating a lab result as evidence about a real organization.
6. Limitations and contribution
Say what was simulated, what was not tested and which steps were your own work. Credit walkthroughs and reused material. Include a safe summary when detailed artifacts cannot be shared.