Digital Forensics & Incident Response
Somebody is in your server, or your site is defaced, and the first thing you want to do is the thing that destroys the evidence. This is what to do instead: preserve, find the entry, build the timeline, find what they left to get back in, and answer honestly whether data was taken.
Not yet reviewed
Before you start
- Linux Fundamentalsabout 6h
- VPS & Self-Hostingabout 6h
This course expects those first. Nothing is locked — sign in and it will say where you stand.
The first thing you want to do is the thing that makes the rest impossible.
One-sided — This course reads evidence rather than producing it. The attack beat lives in the courses that teach the attacks — web security and the attacker's playbook — and every chapter here begins after somebody else has already run one.
2 lessons · 1 hands-on · 7 min
Is it still happening, what is exposed, and what comes down before anything else.
One-sided — Triage is reading and deciding, not attacking. The attack that caused the morning is taught in web security and the attacker's playbook; this chapter starts after it.
1 lesson · 3 min
Finding the single line that mattered among a million that did not.
One-sided — Reading an access log is detection and telemetry only. The requests being read are attacks taught in the web security course; staging one here would repeat that course rather than close a loop.
1 lesson · 1 hands-on · 2 min
When it started, what happened in order, and what has been cleaned.
One-sided — Timeline reconstruction reads evidence. The attack that produced it is taught elsewhere; this chapter begins with the artefacts already on disk.
1 lesson · 3 min
Cleaning the defacement and not the persistence means it happens again on Thursday.
One-sided — This chapter searches a compromised box for what was left behind. Installing persistence is an attacker technique taught in the attacker's playbook.
1 lesson · 1 hands-on · 3 min
The hardest question, and how to answer it honestly rather than reassuringly.
One-sided — Exfiltration as a technique belongs to the attacker's playbook. This chapter is about what evidence of it survives, and about what you may honestly say when it does not.
1 lesson · 3 min
Which backup is safe, what to rebuild rather than clean, and the report that is the actual deliverable.
One-sided — Recovery and reporting produce no attack to pair with. This chapter closes the incident rather than teaching a technique.
1 lesson · 3 min
Labs
Hands-on challenges for this course. Each one hides a flag you have to find.
Exam
Timed, and it issues a credential anyone can verify. Practice quizzes are untimed; this one is not.