Introduction to Go Programming
A beginner level exam on the fundamentals of the Go programming language.
Review Introduction to Go ProgrammingChoose from practical cybersecurity exams covering threat intelligence, incident response, cloud security, malware analysis and defensive research.
Focused challenges designed to test judgment, evidence handling and defensible security decisions.
Pick a focused route instead of searching through internal categories and advisory tags.
Choose a focused assessment aligned with practical course material, from security awareness and cloud security to incident response and software supply chains.
8 assessments Work from sources Investigate real threat reportingUse advisories, standards and technical documentation to answer evidence-led questions without overstating what the sources prove.
62 assessments Think like an analyst Test your intelligence tradecraftAssess requirements, evidence evaluation, analysis, structured intelligence, actor profiling and decision-focused communication.
17 assessments Detect and respond Practice operational security decisionsChallenge your judgment across threat hunting, alert triage, detection engineering, incident reconstruction, forensics and recovery.
22 assessments Protect modern systems Assess trust across connected systemsTest cloud evidence, identity threats, third-party exposure, software dependencies and trusted-release decisions.
28 assessments Follow the operation Trace malicious behavior and infrastructureAnalyze malware behavior, ransomware operations, command infrastructure, delivery chains and defensible investigative pivots.
53 assessmentsA beginner level exam on the fundamentals of the Go programming language.
Review Introduction to Go ProgrammingUse the CISA and U.S. Coast Guard hunt report to decide which observed configuration and logging gaps would prevent defensible incident analysis in an IT/OT environment.
Review AA25-212A Critical-Infrastructure Hunt Gap AnalysisResearch how APT28 used weak SNMP configuration and a known Cisco vulnerability to enumerate routers, deploy Jaguar Tooth, collect network data, and maintain covert access.
Review AA23-108 APT28 Router Exploitation AnalysisExamine the Snake implant's Windows persistence, encrypted artifacts, Queue structure, modular protocol stack, layered encryption, and global peer-to-peer relay design.
Review AA23-129A Snake Implant ArchitectureResearch BianLian's access, proxying, privilege escalation, discovery, credential theft, defense evasion, and changing extortion model from the joint advisory.
Review AA23-136A BianLian Intrusion TradecraftInvestigate CL0P's MOVEit Transfer campaign by connecting the exploited SQL injection to LEMURLOOT authentication, database access, privileged-account behavior, and data theft.
Review AA23-158A MOVEit LEMURLOOT ResearchTrace Truebot from delivery and environment checks through FlawedGrace execution, in-memory follow-on activity, encoded collection, and Teleport exfiltration.
Review AA23-187A Truebot Toolchain InvestigationUse official reporting to distinguish normal Exchange Online access from forged-token activity and choose logging and retention measures that preserve investigative evidence.
Review AA23-193A Outlook Online Audit InvestigationAnalyze appliance-side webshell, privilege, staging, persistence, and anti-forensic artifacts from exploitation of Citrix NetScaler ADC and Gateway systems.
Review AA23-201A Citrix NetScaler Artifact AnalysisInvestigate a vulnerability chain against Ivanti EPMM and use API, log, user-agent, certificate, and webshell evidence to design defensible hunting conclusions.
Review AA23-213A Ivanti EPMM Forensic HuntingResearch QakBot's evolution, tiered command-and-control design, registry persistence, and the operational limits of the 2023 disruption.
Review AA23-242A QakBot Infrastructure ResearchReconstruct two nation-state intrusion paths at an aeronautical organization and connect account, malware, credential, and network evidence to the correct phase of the investigation.
Review AA23-250A Aeronautical Intrusion Timeline AnalysisInvestigate Snatch's RDP entry, bulletproof-hosted command-and-control, long dwell time, service manipulation, Safe Mode boot, shadow-copy removal, filename masquerading, and recovery note.
Review AA23-263A Snatch Safe-Mode Encryption and Dwell-Time AnalysisAnalyze BlackTech's subsidiary-to-headquarters pivots, router firmware replacement, ROMMON bypass, unlogged SSH backdoors, EEM output manipulation, and magic-packet activation.
Review AA23-270A BlackTech Router Firmware and Trusted-Pivot InvestigationUse NSA and CISA assessment findings to analyze ADCS relay, name-resolution poisoning, unsigned SMB, weak network-share controls, cleartext credential discovery, and unrestricted code execution.
Review AA23-278A Active Directory Misconfiguration Exploitation Lab