Abstract

This class is planned and organized to introduce students to the incident response and threat hunting world, and it focus to teach how to setup the best tools, incident response concepts and practical steps, and digital forensics investigation.

Throughout this class we will deep dive into a wide range of topics by starting with Windows Logging, SysMon, ETW and associated investigations. Afterwards, we will cover Windows security, lateral movement and persistence, which are fundamental topics that are used from this point onward. In the next steps the class attendees are introducted to details about incident response and threat hunting processes, and most commom tools and commands used to investigate such incidents and associated potential threats. Two important topics such as Yara and Email Investigation are presented to students, and we show how to collect memory evidences by using free tools. Finally, the course enters in its digital forensic part by investigating file systems, Registry and browsers. At the end, the course presents a section on forensic timeline, which is one of most powerful techniques used to investigate incidents.

This class focus on x86/x64 Windows forensics, but we will use Linux systems as support operating system during most part of the training.

Who Should Attend

This class is meant and organized for professionals who need to learn and increase their knowledge on incident response and threat hunting areas, and are looking for learning comprehensive and practical techniques to use them during digital forensic investigations. Attendees with a specific objective of triaging unknown threats will benefit from this course.

Key Learning Objectives

Students attending this class will:

  • Learn how to setup an appropriate lab of incident response and threat hunting.
  • Master Windows logging.
  • Learn basic concepts about lateral movement and persistence.
  • Learn how to setup necessary monitoring and detection tools such as Suricata and Wazuh.
  • Learn main procedures of incident response and threat hunting.
  • Learn about well-known techniques used in attacks.
  • Master how to use tools and command line operations to detect and understand incidents.
  • Learn how to investigate suspicious emails and how to collect memory appropriately.
  • Learn how to investigate file system, Registry and browser artifacts.
  • ELearn how to create a timeline.

Prerequisite Knowledge

The recommended prior knowledge for attending this class follows below:

  • Class attendees should be prepared to work and install programs on Linux and Windows environments.
  • Students should be ready to use multiple Linux and Windows operating systems commands.
  • Students should have a good foundation on cyber security concepts.
  • A previous experience working on IT infrastructure could be useful.

Lab Requirements

Students must prepare the following lab configuration:

  • Having VMware Workstation, Oracle VirtualBox or Microsoft Hyper-V installed on the system.
  • One virtual machine running Ubuntu 24.04+ or REMnux.
  • One virtual machine running Windows 11 x64.
  • Microsoft Office 365 installed on the Windows virtual machine.
  • Malwoverview installed on both virtual machines, including all necessary APIs already configured.
  • Visual Studio Code installed on both Windows virtual machines.

Additional lab instructions will be sent to students prior the class.

Summary of Training Topics

A brief summary of topics presented in this class follows:

  • Introduction
  • Extra Lab Setup
  • Windows Logging and Investigation
  • Network Detection
  • System Artifacts Acquisition
  • Sandbox
  • Incident Response
  • Threat Information
  • Cyber Attacks
  • IR Hunting Commands
  • Email Investigation
  • File System Acquisition and Analysis
  • Registry Investigation
  • Browser Forensics

Note: Topics can be added, merged or removed without prior notice!