Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend

Tool Path

Sysmon

See what happens on an endpoint. Read process creation and parent/child lineage, network and file and registry activity, tell noise from signal, and correlate events into a short attack timeline — on safe synthetic telemetry.

BeginnerWindows SecurityLog Analysis

Curriculum

  1. 01

    Process Creation & Lineage

    What Sysmon provides, and how process-creation events (with parent, command line and hash) let you reconstruct who spawned what.

    Available
  2. 02

    Network, File & Registry Activity

    Beyond processes: network connections, file creation and registry changes tie an action to what it touched and where it reached out.

    Available
  3. 03

    Configuration, Noise & Correlation

    Sysmon is only as useful as its config: what to include, what to exclude, and how to correlate related events by process GUID and time.

    Available
  4. 04

    Investigation Workflow

    Put it together: from an alert on one event, pivot on the process, gather its lineage/network/file activity, and build the short timeline — then work real telemetry.

    Available

Related learning

SOC Analyst L1