Log Analysis & Alert Triage
SIEM workflow, indicators, context building and prioritization.
A matrix of technical capabilities and tools.
SIEM workflow, indicators, context building and prioritization.
Triage, containment, artifact handling and timeline thinking.
Traffic analysis, protocols, filtering and packet-level reasoning.
Acquisition workflow, integrity checks and forensic copies.
Process, network, injected code and volatile artifact analysis.
Signature-based recovery, validation and artifact reconstruction.
Static and dynamic reasoning around suspicious binaries.
Windows and Linux internals for investigation workflows.
PACKET ANALYSIS
SIEM & XDR
SYSTEM MONITOR
HEX EDITOR
DISK ACQUISITION
MEMORY FORENSICS
PASSWORD AUDIT
REVERSE ENGINEERING
WEB SECURITY