What you'll learn
- Investigate the full attack chain, from initial access to impact
- Know how to detect and mitigate real-world techniques
- Master Windows memory, file system, and timeline analysis
- Learn to scale investigations across an entire enterprise
Module 1
Accessing and Collecting Data

Accessing a Compromised Network
Key Artifacts for DFIR
Kape Data Triage
Kansa Live Triage
Module 2
Initial Access and Execution

Investigating Valid Credentials Abuse
Detecting Public-Facing Exploitation
Investigating Executables Evidence
Investigating PowerShell Execution
Investigating LOLBIN and Fileless
Investigating Script Based Execution
Live Detection With LOKI and THOR
Module 3
Persistence Mechanisms

Detecting Persistent Scheduled Tasks
Detecting Persistent AutoStart Run Keys
Detecting Persistent Malicious Services
Detecting Persistent WMI Consumers
Detecting Persistent Accounts Manipulation
Detecting External Remote Services
Module 4
Credential Access

Windows Credentials
Detecting SAM Hive Dumping
Detecting NTDS Database Dumping
Detecting LSA Secrets Dumping
Module 5
Privilege Escalation

Identifying Windows Service Escalation
Identifying UAC Escalation Bypass
Identifying Access Token Escalation
Identifying DLL Attacks Escalation
Module 6
Domain Malicious Behaviours

Kerberos Tickets
Pass-the-Ticket Attack Detection
AS-REP Roasting and Kerberoasting Detection
DCSync and DCShadow Attacks Detection
Kerberos Delegation Abuse Detection
Microsoft ADCS Abuse Detection
Module 7
Lateral Movement & Pivoting

SMB Lateral Movement Analysis
Detecting WinRM Lateral Movement
PsExec Lateral Movement Analysis
Scheduled Task Lateral Movement Analysis
Investigating Lateral Movement via WMI
Detecting RMM Tools Lateral Movement
Module 8
Exfiltration and Impact

Investigating Data Discovery
Analysing Data Collection
Uncovering Attacker Infrastructure
Identifying Ransomware Operations
Detecting Exfiltration Methods
Tracing Impact Actions
Module 9
Scaling and Timeline Analysis

IR Process at Scale
Velociraptor
Advanced Velociraptor
Plaso Timeline Analysis
Module 10
Memory Analysis

Memory Analysis Introduction
Memory Acquisition
Windows Memory & Processes
Windows Memory & User Activity
Windows Memory & Network
Supplemental Memory
Module 11
Advanced Memory Analysis

MemProcFS Overview
Process Objects Analysis
DLL Injections and Hollowing Analysis
Malicious Drivers and Rootkits Analysis
Module 12
Advanced File System Analysis

FAT32 Analysis
NTFS Analysis
Advanced NTFS Analysis
File Carving

