Overview
Syllabus
Intro
Economics of Security
Evolution of NSM
Symptoms of a Cognitive Crisis
The Cognitive Revolution in DFIR
Investigations as Mental Labyrinths
Navigating the Labyrinth
Studying the Investigation Process
A Scenario-Based Approach to Investigation Analysis
Additional Data Sources
The Compromise
What data did analysts look at first?
Did the first move affect analysis speed
What happens when Bro data replaces
What data sources were viewed most and least frequently?
How many steps were taken to make a disposition judgement
Did analysts investigate friendly or hostile systems first?
Do analysts seek to prove or disprove the alerta
Key Phrase Mapping
Taught by
Security Onion