Encoded PowerShell
Endpoint · T1059.001
Reconstruct a suspicious process chain and identify the strongest escalation evidence.
Investigate / Format preview
Follow realistic alert stories, inspect the available evidence, and decide what the investigation needs next.
This public page shows example topics, not an exercise. To work through published activities and save results, use an approved learner account.
Open learner practiceThese cards describe sample topics; they are not scored exercises on this public page.
Endpoint · T1059.001
Reconstruct a suspicious process chain and identify the strongest escalation evidence.
Identity · T1078
Separate a compromised account from benign remote access using sign-in telemetry.
AWS · IAM
Trace unusual role assumptions and determine the likely blast radius.
Explore the courses that teach the tools and investigation methods used in these practice formats.