Size: 1.52 GB
- Metacognition: Mental models for approaching an investigation
- Evidence: The nuance of investigative data sources, how to interpret them, and how to use your understanding of evidence to drive investigative questioning.
- Questions: How to ask the best investigation questions and how you use reasoning to form heuristics and “rules of thumb”
- Investigation Playbooks: Strategies and templates for building your own investigation playbooks
- Open Source Intel: A framework for understanding context about threats using free open-source tools
- Mise en Place: How to master your environment with any toolset
- The Timeline: Strategies for tracking the investigation process and your findings
- The Curious Hunter: Techniques for finding investigation leads without alerts
- Your Own Worst Enemy: Recognizing and limiting negative bias
- Reporting: effective communication of breaches and false alarms
This course utilizes the Investigation Ninja web application to simulate real investigation scenarios. By taking a vendor agnostic approach, Investigation Ninja provides real world inputs and allows you to query various data sources to uncover evil and decide if an incident has occurred, and what happened. You’ll look through real data and solve unique challenges that will test your newly learned investigation skills. A custom set of labs have been developed specifically for this course. No matter what toolset you work with in your SOC, Investigation Ninja will prepare you to excel in investigations using a data-driven approach.