Skip to contentExploitQuest
LearnDigital Forensics & Incident Response

Digital Forensics & Incident Response

Somebody is in your server, or your site is defaced, and the first thing you want to do is the thing that destroys the evidence. This is what to do instead: preserve, find the entry, build the timeline, find what they left to get back in, and answer honestly whether data was taken.

Medium

Not yet reviewed

7 chapters8 lessons7 practice quizzes2 hands-on labs1 examabout 5hup to 590 XP

Before you start

This course expects those first. Nothing is locked — sign in and it will say where you stand.

Start the courseThe Instinct That Destroys the Case

The first thing you want to do is the thing that makes the rest impossible.

One-sided — This course reads evidence rather than producing it. The attack beat lives in the courses that teach the attacks — web security and the attacker's playbook — and every chapter here begins after somebody else has already run one.

2 lessons · 1 hands-on · 7 min
  1. The Instinct That Destroys the Case4 min
  2. Snapshot, Image, Hashordering3 min
  3. Practice quiz6 questions

Is it still happening, what is exposed, and what comes down before anything else.

One-sided — Triage is reading and deciding, not attacking. The attack that caused the morning is taught in web security and the attacker's playbook; this chapter starts after it.

1 lesson · 3 min
  1. Is It Still Happening3 min
  2. Practice quiz6 questions

Finding the single line that mattered among a million that did not.

One-sided — Reading an access log is detection and telemetry only. The requests being read are attacks taught in the web security course; staging one here would repeat that course rather than close a loop.

1 lesson · 1 hands-on · 2 min
  1. A Million That Failedchallenge2 min
  2. Practice quiz5 questions

When it started, what happened in order, and what has been cleaned.

One-sided — Timeline reconstruction reads evidence. The attack that produced it is taught elsewhere; this chapter begins with the artefacts already on disk.

1 lesson · 3 min
  1. When Did It Start3 min
  2. Practice quiz6 questions

Cleaning the defacement and not the persistence means it happens again on Thursday.

One-sided — This chapter searches a compromised box for what was left behind. Installing persistence is an attacker technique taught in the attacker's playbook.

1 lesson · 1 hands-on · 3 min
  1. Four Places To Lookordering3 min
  2. Practice quiz6 questions

The hardest question, and how to answer it honestly rather than reassuringly.

One-sided — Exfiltration as a technique belongs to the attacker's playbook. This chapter is about what evidence of it survives, and about what you may honestly say when it does not.

1 lesson · 3 min
  1. The Honest Answer3 min
  2. Practice quiz5 questions

Which backup is safe, what to rebuild rather than clean, and the report that is the actual deliverable.

One-sided — Recovery and reporting produce no attack to pair with. This chapter closes the incident rather than teaching a technique.

1 lesson · 3 min
  1. Which Backup Is Safe3 min
  2. Practice quiz7 questions

Labs

Hands-on challenges for this course. Each one hides a flag you have to find.

  1. Everything Is Encrypteddifficulty 3
  2. Somebody Is Already Heredifficulty 3

Exam

Timed, and it issues a credential anyone can verify. Practice quizzes are untimed; this one is not.

  1. Digital Forensics & Incident Response Exam10 questions · pass at 70%