Windows Event IDs
Deck preview · Endpoint
Authentication, process creation, services, and account activity.
Recall / Format preview
Review the high-signal concepts, event IDs, commands, ATT&CK techniques, and investigation patterns defenders use repeatedly.
This public page shows example topics, not an exercise. To work through published activities and save results, use an approved learner account.
Open learner practiceThese cards describe sample topics; they are not scored exercises on this public page.
Deck preview · Endpoint
Authentication, process creation, services, and account activity.
Deck preview · Detection
Techniques, telemetry, and practical detection opportunities.
Deck preview · Cloud
CloudTrail, GuardDuty, IAM, Config, and investigation context.
Explore the courses that teach the tools and investigation methods used in these practice formats.