Skip to main content

What you'll learn

Learn all the skills needed to take you to the next level in your Incident Response and Forensics career.
  • Investigate the full attack chain, from initial access to impact
  • Know how to detect and mitigate real-world techniques
  • Master Windows memory, file system, and timeline analysis
  • Learn to scale investigations across an entire enterprise
12 Modules66 RoomsHard

Module 1

Accessing and Collecting Data

Accessing and Collecting Data
000001100000-------011011011000101000101110-----1111011000101011110101101100000--------------00110100
01011-------------00011110110001010100010111011000010-------101100110001000001001010110010101

Accessing a Compromised Network

Available 16 Sept 2026

Key Artifacts for DFIR

Available 17 Sept 2026

Kape Data Triage

Available 23 Sept 2026

Kansa Live Triage

Available 24 Sept 2026

Module 2

Initial Access and Execution

Initial Access and Execution

Investigating Valid Credentials Abuse

Available 30 Sept 2026

Detecting Public-Facing Exploitation

Available 1 Oct 2026

Investigating Executables Evidence

Available 5 Oct 2026

Investigating PowerShell Execution

Available 7 Oct 2026

Investigating LOLBIN and Fileless

Available 8 Oct 2026

Investigating Script Based Execution

Available 12 Oct 2026

Live Detection With LOKI and THOR

Available 14 Oct 2026

Module 3

Persistence Mechanisms

Persistence Mechanisms

Detecting Persistent Scheduled Tasks

Available 15 Oct 2026

Detecting Persistent AutoStart Run Keys

Available 19 Oct 2026

Detecting Persistent Malicious Services

Available 21 Oct 2026

Detecting Persistent WMI Consumers

Available 22 Oct 2026

Detecting Persistent Accounts Manipulation

Available 26 Oct 2026

Detecting External Remote Services

Available 28 Oct 2026

Module 4

Credential Access

Credential Access

Windows Credentials

Available 29 Oct 2026

Detecting SAM Hive Dumping

Coming soon

Detecting NTDS Database Dumping

Coming soon

Detecting LSA Secrets Dumping

Coming soon

Module 5

Privilege Escalation

Privilege Escalation

Identifying Windows Service Escalation

Coming soon

Identifying UAC Escalation Bypass

Coming soon

Identifying Access Token Escalation

Coming soon

Identifying DLL Attacks Escalation

Coming soon

Module 6

Domain Malicious Behaviours

Domain Malicious Behaviours

Kerberos Tickets

Coming soon

Pass-the-Ticket Attack Detection

Coming soon

AS-REP Roasting and Kerberoasting Detection

Coming soon

DCSync and DCShadow Attacks Detection

Coming soon

Kerberos Delegation Abuse Detection

Coming soon

Microsoft ADCS Abuse Detection

Coming soon

Module 7

Lateral Movement & Pivoting

Lateral Movement & Pivoting

SMB Lateral Movement Analysis

Coming soon

Detecting WinRM Lateral Movement

Coming soon

PsExec Lateral Movement Analysis

Coming soon

Scheduled Task Lateral Movement Analysis

Coming soon

Investigating Lateral Movement via WMI

Coming soon

Detecting RMM Tools Lateral Movement

Coming soon

Module 8

Exfiltration and Impact

Exfiltration and Impact

Investigating Data Discovery

Coming soon

Analysing Data Collection

Coming soon

Uncovering Attacker Infrastructure

Coming soon

Identifying Ransomware Operations

Coming soon

Detecting Exfiltration Methods

Coming soon

Tracing Impact Actions

Coming soon

Module 9

Scaling and Timeline Analysis

Scaling and Timeline Analysis

IR Process at Scale

Coming soon

Velociraptor

Coming soon

Advanced Velociraptor

Coming soon

Plaso Timeline Analysis

Coming soon

Module 10

Memory Analysis

Memory Analysis

Memory Analysis Introduction

Coming soon

Memory Acquisition

Coming soon

Windows Memory & Processes

Coming soon

Windows Memory & User Activity

Coming soon

Windows Memory & Network

Coming soon

Supplemental Memory

Coming soon

Module 11

Advanced Memory Analysis

Advanced Memory Analysis

MemProcFS Overview

Coming soon

Process Objects Analysis

Coming soon

DLL Injections and Hollowing Analysis

Coming soon

Malicious Drivers and Rootkits Analysis

Coming soon

Module 12

Advanced File System Analysis

Advanced File System Analysis

FAT32 Analysis

Coming soon

NTFS Analysis

Coming soon

Advanced NTFS Analysis

Coming soon

File Carving

Coming soon