DFIR / Threat Hunter

For incident response, forensics, malware triage, and hunting. Target role: Investigation and response. Expected timeline: 6-12 months.

GCIH, GCIA, GREM, SC-20035+ resourcesDFIR

Study sequence

  1. Month 1: Windows internals and evidence sources
  2. Months 2-3: PCAP, disk, and memory basics
  3. Months 4-6: malware triage and ATT&CK mapping
  4. Month 6+: hunting hypotheses and response playbooks

Portfolio projects

  • Forensic timeline
  • PCAP investigation report
  • YARA rule and test notes
  • Incident response executive summary