Skip to content

About

Complete notes, lab writeups, and challenge walkthroughs for the LetsDefend Incident Responder Path. This covers DFIR, memory forensics, Windows Event Log analysis, Active Directory attack hunting, malware triage and more!

Topics

Resources

Stars

2 stars

Watchers

0 watching

Forks

Latest commit

 

History

3 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 

Repository files navigation

LetsDefend - Incident Responder Learning Path

Complete notes, labs, and challenge writeups for the LetsDefend Incident Responder certification path

Path Status Author Domain Tools

Certification


What Is This Repository?

This repository documents my completion of the LetsDefend Incident Responder Learning Path - a structured, hands-on curriculum covering the full incident response lifecycle, digital forensics, log analysis, malware triage, Active Directory attack hunting, and security incident reporting.

Every folder contains real course notes, lab walkthroughs, and challenge writeups with screenshots. The notes go beyond bullet-point summaries - they explain why each technique works, what the artifacts look like in a real environment, and how defenders detect the attacks being demonstrated.

If you are studying for a role in DFIR, SOC analysis, threat hunting, or blue team operations, this repository covers the practical skills and tooling you need to build that foundation.


Skills Covered

Domain What You Learn
Incident Response Lifecycle NIST SP 800-61 phases, IR on Windows and Linux, triage methodology
Digital Forensics Memory, disk, registry, browser, USB artifact acquisition and analysis
Log Analysis Windows Event Logs, Sysmon, Advanced Event Log hunting, DFIR log correlation
Malware Analysis Malicious scripts (PowerShell, VBScript), browser extensions, proxy-detected executables
Active Directory Security Kerberoasting, AS-REP Roasting, Golden Ticket, LDAP enumeration, NTDS dumping
Threat Hunting GTFOBins abuse detection, living-off-the-land techniques, lateral movement indicators
Web Server Forensics Apache/Nginx/IIS log analysis, web shell discovery, hacked WordPress investigation
Crisis Management Cyber crisis response planning, communication plans, backup strategy
Reporting Writing security incident reports for technical and executive audiences

Repository Structure

LetsDefend/Incident_Responder/
├── notes/                         # Course notes - one file per lesson
│   ├── 01-Cybersecurity-Incident-Handling-Guide.md
│   ├── 02-Incident-Response-on-Linux.md
│   ├── 02-Incident-Response-on-Windows.md
│   ├── 03-Hacked-Web-Server-Analysis.md
│   ├── 04-Log-Analysis-with-Sysmon.md
│   ├── 05-Forensic-Acquisition-and-Triage.md
│   ├── 06-Memory-Forensics.md
│   ├── 07-Windows-Registry-Forensics.md
│   ├── 08-Event-Log-Analysis.md
│   ├── 09-Browser-Forensics.md
│   ├── 10-GTFOBins.md
│   ├── 11-Hunting-AD-Attacks.md
│   ├── 12-How-to-Prepare-a-Cyber-Crisis-Management-Plan.md
│   ├── 13-Advanced-Event-Log-Analysis.md
│   ├── 14-USB-Forensics.md
│   ├── 15-Windows-Disk-Forensics.md
│   └── 18-Writing-Reports-on-Security-Incidents.md
└── labs/
    ├── active-directory/          # AD attack challenge writeups
    ├── browser-forensics/         # Browser forensics practical cases
    ├── malware-analysis/          # SOC alert and malware challenge writeups
    ├── memory-analysis/           # Memory forensics challenge writeup
    ├── registry-forensics/        # Windows Registry challenge writeup
    └── usb-forensics/             # USB forensics challenge writeup

Course Notes

Detailed notes taken during each lesson in the path. Every note file includes concept explanations, tool usage, key forensic artifact locations, detection logic, and embedded screenshots where applicable.

# Lesson Topics
01 Cybersecurity Incident Handling Guide NIST SP 800-61, IR lifecycle phases, preparation, detection & analysis, containment, eradication, recovery, post-incident activity
02 Incident Response on Linux Linux IR lifecycle, volatile data collection, log sources, user activity analysis, process and network triage, Linux-specific artifacts
02 Incident Response on Windows Windows IR lifecycle, volatile data, prefetch, autoruns, scheduled tasks, service persistence, registry persistence mechanisms
03 Hacked Web Server Analysis Apache / Nginx / IIS log analysis, Tomcat / GlassFish / JBoss attacks, SQLi, XSS, CSRF, PHP and Java vulnerabilities, web shell discovery, hacked WordPress investigation
04 Log Analysis with Sysmon Sysmon installation, configuration and event types, detecting Mimikatz, detecting Pass-the-Hash, detecting privilege escalation via weak service and registry permissions
05 Forensic Acquisition and Triage Memory acquisition (Belkasoft, FTK Imager, AVML), custom disk imaging and mounting, KAPE targets and modules, EZTools, FireEye Redline collectors, Autopsy disk triage
06 Memory Forensics Volatility framework, identifying malicious processes, network connections in memory, detecting process injection, DLL injection, masqueraded processes, memory-resident artifacts
07 Windows Registry Forensics Registry hives and backups, Registry Explorer, system and user info, Shellbags, Shimcache, Amcache, Recent Files, MRU dialogue boxes, forensic tool reference
08 Event Log Analysis Event Viewer, wevtutil, Get-WinEvent, authentication event IDs, logon types, RDP authentication, scheduled tasks, Windows services, account management, event log manipulation, Firewall, Defender, and PowerShell execution logs
09 Browser Forensics Browser artifact acquisition, history, cache, cookies, extensions, BrowsingHistoryView, DB Browser for SQLite, session file analysis, Hindsight framework, recovering deleted browser data
10 GTFOBins Living-off-the-land binaries, shell escapes, non-interactive command execution, reverse and bind shells, file upload and download abuse, sudo abuse, blue team hunting playbook
11 Hunting Active Directory Attacks Active Directory fundamentals, Kerberos authentication deep dive, AS-REP Roasting detection, Kerberoasting detection, LDAP enumeration (BloodHound / SharpHound), NTDS database dumping, Golden Ticket attack detection
12 How to Prepare a Cyber Crisis Management Plan Cyber crisis definition, relevant standards, inventory and communication planning, management and operational response units, backup strategy (3-2-1 and 3-2-1-1-0 rules), crisis end criteria
13 Advanced Event Log Analysis Process creation logging, DNS activity logs, file and folder auditing, BITS client event log, network connection event log, MSI installer logs, Event ID cheat sheet, blue team hunting playbook
14 USB Forensics USB registry keys, USB event logs (Partition / Kernel-PnP / NTFS), Shellbag analysis for folder access, Jumplist analysis for file access, automated USB parser tools, forensic timeline construction
15 Windows Disk Forensics SRUM database (SrumECmd), Jumplists, Recycle Bin artifacts, Windows Search Index, RDP cache, Thumbnail cache, disk forensics artifact cheat sheet
18 Writing Reports on Security Incidents Incident report structure and purpose, intelligibility for technical vs executive audiences, timeline construction, evidence documentation, remediation recommendations, report template

Labs & Challenge Writeups

Hands-on exercises completed as part of the path. Each writeup includes full methodology, tool commands, annotated screenshots, and answers with explanation.

Active Directory

Challenge What It Covers
AS-REP Roasting Detecting AS-REP Roasting via Windows Event Logs - identifying accounts with pre-authentication disabled, analyzing Kerberos TGT request patterns (Event ID 4768), and correlating attacker activity
Golden Ticket Attack Hunting forged Kerberos tickets - analyzing anomalous TGS requests, Event ID 4769 / 4672 correlation, detecting KRBTGT abuse and lateral movement via forged golden tickets
Kerberoasting Identifying Kerberoasting activity - detecting high-volume TGS requests for service accounts, SPN enumeration patterns, offline hash cracking indicators, and the Event IDs that surface the attack
LDAP Enumeration Detecting BloodHound / SharpHound LDAP enumeration - analyzing directory query volume and patterns, identifying reconnaissance activity against AD objects, correlating with lateral movement

Browser Forensics

Lab What It Covers
Practical Case: Insider Threat Browser artifact investigation of a suspected insider threat - history analysis, download records, cookie and session examination to establish timeline of data access and exfiltration
Practical Case: Corporate Policy Violation Investigating corporate policy violations through browser forensics - identifying unauthorized site access, reconstructing user activity timeline, and producing findings for HR/legal handoff

Malware Analysis

Lab / Alert What It Covers
SOC-119 - Proxy: Malicious Executable Detected Investigating a proxy alert for a malicious executable - analyzing network traffic, hash reputation lookup, sandbox detonation, and determining scope and impact
SOC-153 - Suspicious PowerShell Script Executed Decoding and analyzing an obfuscated PowerShell script - deobfuscation techniques, command-line argument analysis, any.run sandbox report review, IOC extraction and containment recommendation
SOC-189 - VBScript Suspicious Behavior Detected Triaging a VBScript-based malware alert - script analysis, behavioral indicators, process tree examination, determining whether the alert is a true positive and escalation path
Challenge: Suspicious Browser Extension Analyzing a malicious browser extension - manifest inspection, permission abuse, background script behavior, data exfiltration indicators, and remediation

Memory Forensics

Challenge What It Covers
Memory Analysis Challenge Full Volatility-based memory investigation - process listing and anomaly detection, network connection analysis, detecting injected code, extracting IOCs from a compromised memory image

Registry Forensics

Challenge What It Covers
Windows Registry Challenge Registry forensics investigation using Registry Explorer - identifying persistence mechanisms, extracting system and user information, Shellbag and Shimcache analysis, MRU and recent file access reconstruction

USB Forensics

Challenge What It Covers
USB Forensics Challenge End-to-end USB device investigation - registry key analysis for first/last connection timestamps, USB event log correlation, Shellbag analysis for folder access, Jumplist analysis for file access, building a complete forensic timeline of USB activity

Tools & Frameworks Referenced

Tool Purpose
Volatility Memory image analysis - process listing, network connections, code injection detection
KAPE Forensic acquisition (targets) and triage (modules) on live Windows systems
FTK Imager Disk and memory image acquisition, image mounting
Autopsy Disk image forensics and artifact extraction
Hindsight Chrome / Chromium browser artifact parsing and deleted data recovery
BrowsingHistoryView Multi-browser history aggregation and timeline reconstruction
Registry Explorer / RECmd Windows registry hive parsing and forensic analysis
Sysmon Windows system monitoring - process creation, network connections, file events
SrumECmd SRUM database parsing for application and network usage history
Eric Zimmerman Tools (EZTools) Suite covering Shellbags, Shimcache, Amcache, Jumplists, MFT, LNK, and more
DB Browser for SQLite Manual browser artifact analysis (history, cookies, downloads databases)
any.run Interactive malware sandbox for dynamic analysis
BloodHound / SharpHound Active Directory enumeration (from the attacker side - covered for detection)
Redline (FireEye/Mandiant) Endpoint triage and IOC sweep
Event Viewer / wevtutil / Get-WinEvent Windows event log querying and analysis

Key Concepts Index

If you are looking for a specific topic, these concepts are covered across the notes and labs:

NIST SP 800-61 · incident response lifecycle · digital forensics · DFIR · memory forensics · Volatility · process injection · DLL injection · Sysmon · Windows Event Logs · Event ID 4624 · Event ID 4625 · Event ID 4688 · Event ID 4769 · Event ID 4768 · Event ID 4672 · Kerberoasting · AS-REP Roasting · Golden Ticket · LDAP enumeration · BloodHound · SharpHound · NTDS dumping · Pass-the-Hash · Mimikatz · Windows Registry forensics · Shellbags · Shimcache · Amcache · MRU · USB forensics · browser forensics · Hindsight · KAPE · FTK Imager · Autopsy · log analysis · Sysmon event types · BITS client logs · process creation logs · DNS activity logs · GTFOBins · living off the land · LOLBAS · web server forensics · Apache log analysis · IIS logs · web shell detection · PowerShell deobfuscation · VBScript malware · browser extension malware · SRUM database · Jumplists · Recycle Bin artifacts · RDP cache · thumbnail cache · Windows Search Index · forensic acquisition · triage · cyber crisis management · 3-2-1 backup rule · incident report writing · SOC analyst · threat hunting · blue team · MITRE ATT&CK


About This Path

The LetsDefend Incident Responder Learning Path is a structured curriculum designed to take analysts from foundational IR concepts through advanced forensic techniques used in real-world investigations. The path combines video lessons, practical exercises, and graded challenges across 15+ modules.

Completing this path builds competency for roles including:

  • SOC Analyst (L1 / L2 / L3)
  • DFIR Analyst
  • Threat Hunter
  • Incident Response Consultant
  • Blue Team Operator

Connect

Prince Lassey - GitHub | LinkedIn | Medium

All writeups are based on authorized LetsDefend lab environments. No real systems were targeted.


Certification

About

Complete notes, lab writeups, and challenge walkthroughs for the LetsDefend Incident Responder Path. This covers DFIR, memory forensics, Windows Event Log analysis, Active Directory attack hunting, malware triage and more!

Topics

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors