← All trainingCourse in Guardian Foundry
Digital Forensics & Incident Response (DFIR)
Investigate endpoint and network evidence with tools including Velociraptor, Volatility, osquery and Hayabusa. Explore execution artifacts, persistence, memory analysis and timelines to reconstruct suspicious activity.
What you’ll practice
- Examine endpoint artifacts for evidence of execution and persistence.
- Use memory and network forensics tools to investigate suspicious activity.
- Build an investigation timeline from event logs and related evidence.
Topics
- Digital forensics
- Incident response
Counts include distinct published activities in this course. Answer-based activities and labs count as exercises; assessments are separate. Repeated activities in a learning path count once.