Skip to main content
← All practice formats

Investigate / Format preview

Scenario investigations

Follow realistic alert stories, inspect the available evidence, and decide what the investigation needs next.

This public page shows example topics, not an exercise. To work through published activities and save results, use an approved learner account.

Open learner practice
Example topics

What you can practice in this format.

These cards describe sample topics; they are not scored exercises on this public page.

01

Encoded PowerShell

Endpoint · T1059.001

Reconstruct a suspicious process chain and identify the strongest escalation evidence.

02

Impossible travel

Identity · T1078

Separate a compromised account from benign remote access using sign-in telemetry.

03

CloudTrail anomaly

AWS · IAM

Trace unusual role assumptions and determine the likely blast radius.

Skills you develop

Practice with a clear purpose.

  • Structure an investigation
  • Prioritize evidence
  • Map behavior to ATT&CK
  • Write a defensible conclusion
Find the training

Build the knowledge behind the exercise.

Explore the courses that teach the tools and investigation methods used in these practice formats.

Browse training programs