Skip to main content
Back to all walkthroughs
Room Icon

Introduction to Windows IR

Begin your journey into incident response for Windows and Active Directory.

easy

60 min

3,325

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

Active Directory remains a core technology for enterprises; by most estimates, around 95% of Fortune 500 companies use it. As a result, most ransomware attacks target environments, and you must know AD and Windows internals to respond properly. Throughout the path, you'll see how AD attacks occur from the adversary's point of view and gain technical skills to detect them, using both logs and forensic artifacts.

Isometric illustration of an analyst at a control desk looking at a network map, watching server racks spread across a world map. One rack glows red, showing a hacked server among systems around the world.

Path Structure

This path is mapped to ATT&CK and focuses on the most common techniques observed in real-world intrusions. By the end, you'll know how to detect, investigate, and defend against roughly 100 techniques shown below. Note that the L2 path isn't a strict prerequisite, but it's a great addition and covers most gaps in this path.

A MITRE ATT&CK matrix showing the techniques covered in the Windows incident response path, with ~100 of the techniques marked as covered.
MITRE techniques covered in the Windows path (in green)

Who Is It For

  • professionals seeking practice with real-world incidents
  • Security experts preparing for advanced blue-team certifications
  • SOC analysts and engineers expanding into the DFIR world
  • Red teamers wanting a defensive view of their engagements
  • Other roles may still find some of the rooms valuable to:
    • See how the Windows works behind the scenes
    • Learn the mindset of attackers and defenders
    • Explore mitigations against attacks on Windows
Answer the questions below

Let's go!

You'll start with a preparation module most valuable for external teams: how to communicate with the customer, access the network, and collect forensic artifacts. In the next modules, you'll go technical and explore the most common ATT&CK techniques seen in intrusions, from Initial Access and to Exfiltration and Impact. Most rooms follow the same three-part structure:

IR Course Plan Illustration.

Learning Objectives

  • Learn how to start the process on a Windows environment
  • Discover how to communicate with the customer during IR
  • Explore DefenseBox and learn how to prepare your DFIR lab

Prerequisites

  • Knowledge of IR and Windows fundamentals
  • Completion of the  Level 2 path would help
Answer the questions below

Move on to the next task.

You are an external specialist hired by OpenDoor LTD, a large UK-based real estate company, to investigate a security incident. A 2,500-user Active Directory network has been compromised, and data has been exfiltrated. Somehow, the didn't generate any alerts, but OpenDoor's IT team noticed the attack and isolated the network before ransomware encryption. Now, it's your turn.

Mobilize Resources

First, gather everything you need for IR, both from your end and the customer's. You might be lucky and have an IR coordinator who handles the organizational questions and leaves the technical work to you. Often, however, you need to manage the communication from start to finish. Either way, it's vital to meet the customer and gather a small but effective DFIR team. It's better to have 3 dedicated experts than 20 analysts who switch between shifts and DFIR work.

A flowchart of the incident response kickoff. Your manager tells you (the DFIR expert) about the incident and shares OpenDoor's contacts. You reach out to a contact (usually CEO/CISO/CTO), who gathers OpenDoor's incident team. You also gather your own DFIR team, then everyone joins a video call.

Organize Intro Call

Once the DFIR team is gathered and you've established contact with OpenDoor's representative via phone or email, organize an intro call with the customer. Schedule it as soon as possible, even on a weekend night. Ask the customer to invite at least one technical employee who knows about the incident (usually the IT team), and ideally the CEO, CISO, or , to meet your team and observe the process. On the call, introduce yourself and the team, enable meeting notes, and ask the questions below:

Incident Details Company Profile
  • What actually happened and when?
  • Who detected the incident and how?
  • Which systems/locations are affected?
  • Did you perform any response actions?
  • Any assumptions on how the attack started?
  • Any indicators (files/) you already found?
  • How does your network look?
  • What entry points exist (e.g., )?
  • What services are internet-exposed?
  • Which /EDR/ do you have?
  • What are your expectations from us?
  • Who can support us during the DFIR?

If you hear the customer made mistakes that can affect DFIR, such as "we saw some suspicious files and already deleted them", urgently explain what the customer shouldn't do throughout the incident response. Luckily, OpenDoor's team contained the threat and preserved the evidence correctly, so you can just ask your questions and answer theirs.

Practice

You're on a call with OpenDoor, where you are leading the DFIR team, and Oliver from OpenDoor's IT department is the most active participant. Click the Open Agent button above, ask what you want about the company and the incident, and answer the task questions. Keep in mind that not everyone is on the call, so you might not get all the answers you want.

Answer the questions below

Where is the affected data center located?

Whom does OpenDoor suspect of starting the attack?

Did OpenDoor manage to find any indicators of compromise?
Answer Format: Indicator, Host

What EDR is deployed across OpenDoor's network?

Organize Chat

Once the intro call is done, set up a dedicated incident chat. You can still set up periodic meetings, but a chat is a must-have for live communication, as it keeps a searchable history and lets you ask small questions asynchronously, any time. Aim to focus on a single chat, often called the "war room". Ask the customer to invite only trusted members who can actively contribute to the DFIR, such as people from these teams:

  • IT Team: Technical experts who can grant you access or guide you through the network architecture
  • Security Team: , InfoSec, or other teams that were handling the incident before you joined
  • or CISO: A representative from top management to oversee the whole incident response
  • Depending on the case, you may also need representatives from legal or teams

A diagram of the War Room (main IR chat) holding your DFIR team and OpenDoor's incident team. To consult outside partners, share limited context and pass the response back; for HR questions, ask directly and pass the response. Text advises keeping the war room to 5-10 people for OPSEC.

Keep the war room simple but effective, ideally 5-10 people.
Don't invite unnecessary people for purposes (next section)

OPSEC and Chats

Keep in mind that the customer's accounts and devices might be compromised, and attackers may be silently reading all conversations. Moreover, hackers sometimes publicly leak their victims' chats to prove the breach and simply show off, which causes reputational damage to the customer - and even more to you as a DFIR expert. For major incidents like the one at OpenDoor, follow these basic Operations Security (OPSEC) rules:

OPSEC Rule Explanation
Don't chat over a corporate channel It is very common for adversaries to spy on corporate Teams and Slack using compromised IT accounts (see the screenshot below).
Use end-to-end encrypted messengers Signal and WhatsApp are your best choices: end-to-end encrypted, and their sessions are harder to replay on another malicious device.
Secure devices of chat members Adversaries may still export the conversations from the infected device. To prevent this, investigate the hosts of chat members as a high priority.

Screenshot of a Microsoft Teams incident response chat titled "[Cyberprotect] Réponse à incident" with a Ragnar Locker skull logo and watermark overlaid. Caption notes this is a redacted version of Ragnar Locker's screen capture of their victim's IR chat, showing the attackers had infiltrated the response channel.

Redacted version of Ragnar Locker's screen capture of their victim's IR chat (SC Media (opens in new tab))

Communication Pitfalls

The main pitfall you'll hit with a client is overtrusting their statements. The customer's IT surely knows their network, but they can make mistakes; it's also easier to say "our network is segmented and passwords are strong" than to admit the real state of things. Beyond that, make sure you actually understand each other before drawing conclusions, since the same phrasing can mean different things to you and to them. For example:

  • Our network is "segmented" - but all traffic is allowed between subnets
  • is "enabled" - but it's not enforced, and nobody actually uses it
  • Public is "disabled" - but it remained enabled during the incident

Playbook to Avoid Pitfalls

A "Playbook to Avoid Pitfalls" flowchart for validating customer statements. Steps: receive a statement, ask clarifying questions, rephrase it, then check if the customer confirmed. If no, loop back to rephrasing; if yes, verify with logs when needed and check if evidence matches. If no, loop back; if yes, done.

Practice

Continue your conversation with OpenDoor. Click the Open Agent button above, try to convince them to create a DFIR chat, and solve the mystery of why the you found in Task 3 didn't generate any alerts throughout the whole attack. You should find the right words in the task's content. Good luck!

Answer the questions below

What EDR is really in use by OpenDoor?

How many hosts are actually protected with EDR?

Convince OpenDoor to create a secure chat.
What chat invitation code do you get?

Minimal Lab Setup

As soon as the incident response starts, prepare the lab environment. Your first minimum requirement is a Windows machine with all necessary tools installed, where you will analyze acquired artifacts and forward them to sandboxes or specialized VMs, if required. You can also work from macOS or , but it is generally more intuitive to analyze Windows artifacts from a Windows . Throughout the path, we will use DefenseBox, a custom-built machine to analyze DFIR artifacts:

DefenseBox screenshot.

Evidence Storage

The second must-have item is evidence storage where you and the customer will exchange collected artifacts, DFIR scripts, and agents, if required. A cloud option like Google Drive would work, but keep in mind that a forensic-focused storage would be better. Ideal storage should cover the main Google Drive features, plus:

  • Be private (most cloud vendors do OCR and scan the uploaded files)
  • Be performant (no speed limits; close to you and the customer)
  • Have audit logs (log who uploads, changes, or deletes the files)
  • Not block access to the uploaded files classified as malware

Advanced DFIR Lab

For large investigations such as the OpenDoor breach, you may need to build a separate DFIR lab. For example, a Linux can be useful for tasks where Windows is not ideal, such as debugging Node.js malware or running pentest tools to verify attack steps. If you're working with large volumes of logs (e.g., 2 GB of logs), it's best to ingest them into a , enrich them with GeoIP and reputation lookups, and analyze them there rather than struggling in a text editor. You may also want:

  • An air-gapped VM to analyze malware without infection risk
  • A syslog receiver for live logs from compromised firewalls and appliances
  • Velociraptor or EDR agents on compromised hosts (will be covered in later rooms)

A DFIR lab architecture diagram. A DFIR Lab zone (no internet) holds Windows and Linux DFIR VMs, a Sandbox VM, and a SIEM like Splunk. A DMZ zone (internet-facing) holds a Velociraptor/EDR server and a Syslog Receiver. The compromised network sends data through a firewall and the internet to the EDR and to evidence storage, which feeds the SIEM.

Once the lab is ready, connect to it and collect/analyze artifacts from there

DefenseBox Practice

Launch DefenseBox by clicking Start DefenseBox and explore what's on it. You can also connect over OpenVPN and using the credentials below.

  • User: DFIRUser
  • Password: Secure!
AttackBox card placeholder

For all future DFIR rooms, we highly recommend accessing DefenseBox and the target VM over OpenVPN and connecting via RDP. This speeds up triage and makes switching between the VMs easier.

Answer the questions below

What tool was recommended for analyzing large amounts of logs?

Launch DefenseBox and open the Usage Guide.
What flag do you see at the bottom of the web page?

Now open the DFIR Tools folder on the desktop.
What's the first tool in the Artifact Collection folder?

What's Next

Today we've covered the organizational stage of Windows Incident Response: how to communicate with the customer and how to prepare your lab. In the next room, we'll continue OpenDoor's storyline, access their network, collect forensic artifacts, and use them to uncover the breach.

Answer the questions below

Complete the room!