Complete notes, labs, and challenge writeups for the LetsDefend Incident Responder certification path
This repository documents my completion of the LetsDefend Incident Responder Learning Path - a structured, hands-on curriculum covering the full incident response lifecycle, digital forensics, log analysis, malware triage, Active Directory attack hunting, and security incident reporting.
Every folder contains real course notes, lab walkthroughs, and challenge writeups with screenshots. The notes go beyond bullet-point summaries - they explain why each technique works, what the artifacts look like in a real environment, and how defenders detect the attacks being demonstrated.
If you are studying for a role in DFIR, SOC analysis, threat hunting, or blue team operations, this repository covers the practical skills and tooling you need to build that foundation.
| Domain | What You Learn |
|---|---|
| Incident Response Lifecycle | NIST SP 800-61 phases, IR on Windows and Linux, triage methodology |
| Digital Forensics | Memory, disk, registry, browser, USB artifact acquisition and analysis |
| Log Analysis | Windows Event Logs, Sysmon, Advanced Event Log hunting, DFIR log correlation |
| Malware Analysis | Malicious scripts (PowerShell, VBScript), browser extensions, proxy-detected executables |
| Active Directory Security | Kerberoasting, AS-REP Roasting, Golden Ticket, LDAP enumeration, NTDS dumping |
| Threat Hunting | GTFOBins abuse detection, living-off-the-land techniques, lateral movement indicators |
| Web Server Forensics | Apache/Nginx/IIS log analysis, web shell discovery, hacked WordPress investigation |
| Crisis Management | Cyber crisis response planning, communication plans, backup strategy |
| Reporting | Writing security incident reports for technical and executive audiences |
LetsDefend/Incident_Responder/
├── notes/ # Course notes - one file per lesson
│ ├── 01-Cybersecurity-Incident-Handling-Guide.md
│ ├── 02-Incident-Response-on-Linux.md
│ ├── 02-Incident-Response-on-Windows.md
│ ├── 03-Hacked-Web-Server-Analysis.md
│ ├── 04-Log-Analysis-with-Sysmon.md
│ ├── 05-Forensic-Acquisition-and-Triage.md
│ ├── 06-Memory-Forensics.md
│ ├── 07-Windows-Registry-Forensics.md
│ ├── 08-Event-Log-Analysis.md
│ ├── 09-Browser-Forensics.md
│ ├── 10-GTFOBins.md
│ ├── 11-Hunting-AD-Attacks.md
│ ├── 12-How-to-Prepare-a-Cyber-Crisis-Management-Plan.md
│ ├── 13-Advanced-Event-Log-Analysis.md
│ ├── 14-USB-Forensics.md
│ ├── 15-Windows-Disk-Forensics.md
│ └── 18-Writing-Reports-on-Security-Incidents.md
└── labs/
├── active-directory/ # AD attack challenge writeups
├── browser-forensics/ # Browser forensics practical cases
├── malware-analysis/ # SOC alert and malware challenge writeups
├── memory-analysis/ # Memory forensics challenge writeup
├── registry-forensics/ # Windows Registry challenge writeup
└── usb-forensics/ # USB forensics challenge writeup
Detailed notes taken during each lesson in the path. Every note file includes concept explanations, tool usage, key forensic artifact locations, detection logic, and embedded screenshots where applicable.
| # | Lesson | Topics |
|---|---|---|
| 01 | Cybersecurity Incident Handling Guide | NIST SP 800-61, IR lifecycle phases, preparation, detection & analysis, containment, eradication, recovery, post-incident activity |
| 02 | Incident Response on Linux | Linux IR lifecycle, volatile data collection, log sources, user activity analysis, process and network triage, Linux-specific artifacts |
| 02 | Incident Response on Windows | Windows IR lifecycle, volatile data, prefetch, autoruns, scheduled tasks, service persistence, registry persistence mechanisms |
| 03 | Hacked Web Server Analysis | Apache / Nginx / IIS log analysis, Tomcat / GlassFish / JBoss attacks, SQLi, XSS, CSRF, PHP and Java vulnerabilities, web shell discovery, hacked WordPress investigation |
| 04 | Log Analysis with Sysmon | Sysmon installation, configuration and event types, detecting Mimikatz, detecting Pass-the-Hash, detecting privilege escalation via weak service and registry permissions |
| 05 | Forensic Acquisition and Triage | Memory acquisition (Belkasoft, FTK Imager, AVML), custom disk imaging and mounting, KAPE targets and modules, EZTools, FireEye Redline collectors, Autopsy disk triage |
| 06 | Memory Forensics | Volatility framework, identifying malicious processes, network connections in memory, detecting process injection, DLL injection, masqueraded processes, memory-resident artifacts |
| 07 | Windows Registry Forensics | Registry hives and backups, Registry Explorer, system and user info, Shellbags, Shimcache, Amcache, Recent Files, MRU dialogue boxes, forensic tool reference |
| 08 | Event Log Analysis | Event Viewer, wevtutil, Get-WinEvent, authentication event IDs, logon types, RDP authentication, scheduled tasks, Windows services, account management, event log manipulation, Firewall, Defender, and PowerShell execution logs |
| 09 | Browser Forensics | Browser artifact acquisition, history, cache, cookies, extensions, BrowsingHistoryView, DB Browser for SQLite, session file analysis, Hindsight framework, recovering deleted browser data |
| 10 | GTFOBins | Living-off-the-land binaries, shell escapes, non-interactive command execution, reverse and bind shells, file upload and download abuse, sudo abuse, blue team hunting playbook |
| 11 | Hunting Active Directory Attacks | Active Directory fundamentals, Kerberos authentication deep dive, AS-REP Roasting detection, Kerberoasting detection, LDAP enumeration (BloodHound / SharpHound), NTDS database dumping, Golden Ticket attack detection |
| 12 | How to Prepare a Cyber Crisis Management Plan | Cyber crisis definition, relevant standards, inventory and communication planning, management and operational response units, backup strategy (3-2-1 and 3-2-1-1-0 rules), crisis end criteria |
| 13 | Advanced Event Log Analysis | Process creation logging, DNS activity logs, file and folder auditing, BITS client event log, network connection event log, MSI installer logs, Event ID cheat sheet, blue team hunting playbook |
| 14 | USB Forensics | USB registry keys, USB event logs (Partition / Kernel-PnP / NTFS), Shellbag analysis for folder access, Jumplist analysis for file access, automated USB parser tools, forensic timeline construction |
| 15 | Windows Disk Forensics | SRUM database (SrumECmd), Jumplists, Recycle Bin artifacts, Windows Search Index, RDP cache, Thumbnail cache, disk forensics artifact cheat sheet |
| 18 | Writing Reports on Security Incidents | Incident report structure and purpose, intelligibility for technical vs executive audiences, timeline construction, evidence documentation, remediation recommendations, report template |
Hands-on exercises completed as part of the path. Each writeup includes full methodology, tool commands, annotated screenshots, and answers with explanation.
| Challenge | What It Covers |
|---|---|
| AS-REP Roasting | Detecting AS-REP Roasting via Windows Event Logs - identifying accounts with pre-authentication disabled, analyzing Kerberos TGT request patterns (Event ID 4768), and correlating attacker activity |
| Golden Ticket Attack | Hunting forged Kerberos tickets - analyzing anomalous TGS requests, Event ID 4769 / 4672 correlation, detecting KRBTGT abuse and lateral movement via forged golden tickets |
| Kerberoasting | Identifying Kerberoasting activity - detecting high-volume TGS requests for service accounts, SPN enumeration patterns, offline hash cracking indicators, and the Event IDs that surface the attack |
| LDAP Enumeration | Detecting BloodHound / SharpHound LDAP enumeration - analyzing directory query volume and patterns, identifying reconnaissance activity against AD objects, correlating with lateral movement |
| Lab | What It Covers |
|---|---|
| Practical Case: Insider Threat | Browser artifact investigation of a suspected insider threat - history analysis, download records, cookie and session examination to establish timeline of data access and exfiltration |
| Practical Case: Corporate Policy Violation | Investigating corporate policy violations through browser forensics - identifying unauthorized site access, reconstructing user activity timeline, and producing findings for HR/legal handoff |
| Lab / Alert | What It Covers |
|---|---|
| SOC-119 - Proxy: Malicious Executable Detected | Investigating a proxy alert for a malicious executable - analyzing network traffic, hash reputation lookup, sandbox detonation, and determining scope and impact |
| SOC-153 - Suspicious PowerShell Script Executed | Decoding and analyzing an obfuscated PowerShell script - deobfuscation techniques, command-line argument analysis, any.run sandbox report review, IOC extraction and containment recommendation |
| SOC-189 - VBScript Suspicious Behavior Detected | Triaging a VBScript-based malware alert - script analysis, behavioral indicators, process tree examination, determining whether the alert is a true positive and escalation path |
| Challenge: Suspicious Browser Extension | Analyzing a malicious browser extension - manifest inspection, permission abuse, background script behavior, data exfiltration indicators, and remediation |
| Challenge | What It Covers |
|---|---|
| Memory Analysis Challenge | Full Volatility-based memory investigation - process listing and anomaly detection, network connection analysis, detecting injected code, extracting IOCs from a compromised memory image |
| Challenge | What It Covers |
|---|---|
| Windows Registry Challenge | Registry forensics investigation using Registry Explorer - identifying persistence mechanisms, extracting system and user information, Shellbag and Shimcache analysis, MRU and recent file access reconstruction |
| Challenge | What It Covers |
|---|---|
| USB Forensics Challenge | End-to-end USB device investigation - registry key analysis for first/last connection timestamps, USB event log correlation, Shellbag analysis for folder access, Jumplist analysis for file access, building a complete forensic timeline of USB activity |
| Tool | Purpose |
|---|---|
| Volatility | Memory image analysis - process listing, network connections, code injection detection |
| KAPE | Forensic acquisition (targets) and triage (modules) on live Windows systems |
| FTK Imager | Disk and memory image acquisition, image mounting |
| Autopsy | Disk image forensics and artifact extraction |
| Hindsight | Chrome / Chromium browser artifact parsing and deleted data recovery |
| BrowsingHistoryView | Multi-browser history aggregation and timeline reconstruction |
| Registry Explorer / RECmd | Windows registry hive parsing and forensic analysis |
| Sysmon | Windows system monitoring - process creation, network connections, file events |
| SrumECmd | SRUM database parsing for application and network usage history |
| Eric Zimmerman Tools (EZTools) | Suite covering Shellbags, Shimcache, Amcache, Jumplists, MFT, LNK, and more |
| DB Browser for SQLite | Manual browser artifact analysis (history, cookies, downloads databases) |
| any.run | Interactive malware sandbox for dynamic analysis |
| BloodHound / SharpHound | Active Directory enumeration (from the attacker side - covered for detection) |
| Redline (FireEye/Mandiant) | Endpoint triage and IOC sweep |
| Event Viewer / wevtutil / Get-WinEvent | Windows event log querying and analysis |
If you are looking for a specific topic, these concepts are covered across the notes and labs:
NIST SP 800-61 · incident response lifecycle · digital forensics · DFIR · memory forensics · Volatility · process injection · DLL injection · Sysmon · Windows Event Logs · Event ID 4624 · Event ID 4625 · Event ID 4688 · Event ID 4769 · Event ID 4768 · Event ID 4672 · Kerberoasting · AS-REP Roasting · Golden Ticket · LDAP enumeration · BloodHound · SharpHound · NTDS dumping · Pass-the-Hash · Mimikatz · Windows Registry forensics · Shellbags · Shimcache · Amcache · MRU · USB forensics · browser forensics · Hindsight · KAPE · FTK Imager · Autopsy · log analysis · Sysmon event types · BITS client logs · process creation logs · DNS activity logs · GTFOBins · living off the land · LOLBAS · web server forensics · Apache log analysis · IIS logs · web shell detection · PowerShell deobfuscation · VBScript malware · browser extension malware · SRUM database · Jumplists · Recycle Bin artifacts · RDP cache · thumbnail cache · Windows Search Index · forensic acquisition · triage · cyber crisis management · 3-2-1 backup rule · incident report writing · SOC analyst · threat hunting · blue team · MITRE ATT&CK
The LetsDefend Incident Responder Learning Path is a structured curriculum designed to take analysts from foundational IR concepts through advanced forensic techniques used in real-world investigations. The path combines video lessons, practical exercises, and graded challenges across 15+ modules.
Completing this path builds competency for roles including:
- SOC Analyst (L1 / L2 / L3)
- DFIR Analyst
- Threat Hunter
- Incident Response Consultant
- Blue Team Operator
Prince Lassey - GitHub | LinkedIn | Medium
All writeups are based on authorized LetsDefend lab environments. No real systems were targeted.

