DFIR roadmap

Investigate incidents, collect evidence, and rebuild attack timelines. Practice alert triage, then disk, memory, endpoint, and cloud forensics.

3 courses11 resourcesDFIR / threat hunter

Step-by-step path

  1. Windows and Linux artifacts
  2. PCAP, log, and SIEM investigations
  3. Timeline, containment, and incident reports
  4. Build a portfolio artifact and publish a short writeup.