DNS Investigations: Resolution, Telemetry, and Threat Decisions
A practical analyst course for tracing DNS resolution, reading records and caches, working with resolver telemetry, and turning suspicious queries into scoped security decisions.
Browse our selection of courses and level up your knowledge.
A practical analyst course for tracing DNS resolution, reading records and caches, working with resolver telemetry, and turning suspicious queries into scoped security decisions.
A practical course for reconstructing Windows execution, reading command lines, separating signed tools from trusted behavior, and correlating process trees with endpoint impact.
A hands-on analyst course for examining suspicious email safely, interpreting authentication and routing evidence, scoping exposure, and recording a defensible disposition.
A daily-practice course for turning noisy alerts into bounded evidence, tested hypotheses, proportionate severity, and case notes responders can act on.
A field course for reading Windows logon, Kerberos, and NTLM evidence across workstations, servers, and domain controllers without reducing investigations to event-ID lookups.
A conceptual overview of Cyber Threat Intelligence for absolute beginners.
A practitioner-focused course on CVE identifiers, vulnerability lifecycle analysis, CVSS interpretation, exploitation context, prioritization, and intelligence-driven remediation d...
Learn to turn cyber evidence into defensible, decision-relevant intelligence through requirements, collection, structured analysis, adversary behavior modeling, communication, and ...
Learn how OSINT practitioners discover, evaluate, corroborate, analyze, and communicate intelligence derived from publicly available information.
Learn to transform threat trends, organizational exposure, and uncertainty into strategic scenarios, risk judgments, executive options, and defensible security investment decisions...
Advance from CTI foundations to operational investigations, evidence reconstruction, infrastructure analysis, campaign assessment, time-sensitive reporting, and intelligence-led de...