What you'll learn
- Investigate the full attack chain, from initial access to impact
- Know how to detect and mitigate real-world techniques
- Master Windows memory, file system, and timeline analysis
- Learn to scale investigations across an entire enterprise
Module 1
Accessing and Collecting Data

Kansa Live Triage
Module 2
Initial Access and Execution
Investigating Valid Credentials Abuse
Investigating Public-Facing Exploitation
Investigating Executables Evidence
Investigating PowerShell Execution
Investigating LOLBIN and Fileless
Investigating Script Based Executions
Live Detection With LOKI and THOR
Module 3
Persistence Mechanisms
Detecting Persistent Scheduled Tasks
Detecting Persistent AutoStart Run Keys
Detecting Persistent Malicious Services
Detecting Persistent WMI Consumers
Detecting Persistent Accounts Manipulation
Detecting External Remote Services
Module 4
Credential Access
Windows Credentials
Detecting SAM Hive Dumping
Detecting NTDS Database Dumping
Detecting LSA Secrets Dumping
Module 5
Privilege Escalation
Identifying Windows Service Escalation
Identifying UAC Escalation Bypass
Identifying Access Token Escalation
Identifying DLL Attacks Escalation
Module 6
Domain Malicious Behaviours
Kerberos Tickets
Pass-the-Ticket Attack Detection
Kerberoasting and AS-REP Roasting Detection
DCSync and DCShadow Attacks Detection
Kerberos Delegation Abuse Detection
Microsoft ADCS Abuse Detection
Module 7
Lateral Movement & Pivoting
SMB Lateral Movement Analysis
Detecting WinRM Lateral Movement
PsExec Lateral Movement Analysis
Scheduled Task Lateral Movement Analysis
Investigating Lateral Movement via WMI
Detecting RMM Tools Lateral Movement
Module 8
Exfiltration and Impact
Investigating Data Discovery
Analysing Data Collection
Uncovering Attacker Infrastructure
Identifying Ransomware Operations
Detecting Exfiltration Methods
Tracing Impact Actions
Module 9
Scaling and Timeline Analysis
IR Process at Scale
Velociraptor
Advanced Velociraptor
Plaso Timeline Analysis
Module 10
Memory Analysis
Memory Analysis Introduction
Memory Acquisition
Windows Memory & Processes
Windows Memory & User Activity
Windows Memory & Network
Supplemental Memory
Module 11
Advanced Memory Analysis
MemProcFS Overview
Process Objects Analysis
DLL Injections and Hollowing Analysis
Malicious Drivers and Rootkits Analysis
Module 12
Advanced File System Analysis
FAT32 Analysis
NTFS Analysis
Advanced NTFS Analysis
File Carving

