Endpoint investigation and containment
Containment is where inexperienced responders do the most damage. This session works the endpoint end to end: what the attacker reached, what to preserve, and how to isolate without burning the investigation.
- When
- Sat 31 Oct 2026 · 10:30–13:30 IST
- Where
- Bangalore or virtual
- Cohort size
- 25 in person · 40 including virtual
Sessions can be booked individually, or take the full six-session cohort.
What you leave able to do
- Establish scope on a compromised endpoint
- Contain an active intrusion without destroying evidence
- Produce a defensible timeline of attacker activity
Run of play
- 1
Scope
What did the attacker actually reach, and how would you know?
- 2
Containment
Isolating the host while preserving what the investigation needs.
The case
Where this sits in the story
All six Saturdays run on one continuous breach, so every session picks up where the last one left off.
What started as SSH noise is now a confirmed intrusion with Silent Phantom's fingerprints. Sam Carter takes over for the forensic timeline. A Word macro emailed to three staff turns out to be the initial access vector, and the trail runs from that document through to LSASS.
Who this session suits
Analysts ready for full investigations. The heaviest hands-on session of the cohort — nine labs, and the point where triage becomes forensics.
Scope
What this session covers
- Endpoint forensics: process trees, persistence, PsExec/WMI/RDP lateral movement
- Threat intel fundamentals and the IOC lifecycle
- PCAP analysis with tshark, and beaconing jitter in EDR telemetry
- OSINT attribution, and why a Tor exit node names nobody
- Reversing VBA macros: AutoOpen, embedded URLs, Base64 PowerShell
- The full phishing playbook end to end, headers through memory
- Windows EVTX forensics with PowerShell across 14,000 events
- Insider threat classification and order of volatility
- The endpoint playbook in KQL, document to credential theft, with dwell time
Hands-on
The labs you work
9 hands-on labs, 545 minutes of lab time. Each runs in a cloud terminal against real evidence — logs, PCAPs, event data — and is graded on what you find, not on a multiple-choice answer. Lab access continues for 3 months, so the work does not stop when the session ends.
- 1Endpoint Investigation and Forensicssoc-foundations70 min
- 2Threat Intelligence Fundamentalssoc-sentinel-ready55 min
- 3Network Traffic Analysis and Triagesoc-sentinel-ready65 min
- 4OSINT & Attacker Attributionsoc-sentinel-ready50 min
- 5Macro-Enabled Document Analysissoc-sentinel-ready55 min
- 6Phishing Investigation Playbook with KQLsoc-sentinel-ready70 min
- 7Windows Security Event Log Forensics with PowerShellsoc-sentinel-ready60 min
- 8Insider Threats & User Behaviour Analyticssoc-sentinel-ready55 min
- 9Endpoint Malware Triage with KQLsoc-sentinel-ready65 min
Tools used
- tshark / PCAP
- PowerShell
- KQL
- VirusTotal
- MISP
- Shodan
- jq
MITRE ATT&CK coverage (36)
- T1003.001 OS Credential Dumping: LSASS Memory
- T1005 Data from Local System
- T1021.001 Remote Services: Remote Desktop Protocol
- T1021.002 Remote Services: SMB/Windows Admin Shares
- T1027 Obfuscated Files or Information
- T1039 Data from Network Shared Drive
- T1041 Exfiltration Over C2 Channel
- T1047 Windows Management Instrumentation
- T1048 Exfiltration Over Alternative Protocol
- T1055 Process Injection
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1059.003 Command and Scripting Interpreter: Windows Command Shell
- T1068 Exploitation for Privilege Escalation
- T1069.002 Permission Groups Discovery: Domain Groups
- T1071.001 Application Layer Protocol: Web Protocols
- T1071.004 Application Layer Protocol: DNS
- T1074.001 Data Staged: Local Data Staging
- T1078 Valid Accounts
- T1087 Account Discovery
- T1087.002 Account Discovery: Domain Account
- T1105 Ingress Tool Transfer
- T1110.003 Brute Force: Password Spraying
- T1114.001 Email Collection: Local Email Collection
- T1119 Automated Collection
- T1134 Access Token Manipulation
- T1134.001 Access Token Manipulation: Token Impersonation/Theft
- T1190 Exploit Public-Facing Application
- T1195.002 Supply Chain Compromise: Compromise Software Supply Chain
- T1547.001 Boot or Logon Autostart: Registry Run Keys
- T1548 Abuse Elevation Control Mechanism
- T1550.002 Use Alternate Authentication Material: Pass the Hash
- T1566.001 Phishing: Spearphishing Attachment
- T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
- T1589 Gather Victim Identity Information
- T1590 Gather Victim Network Information
- T1591 Gather Victim Org Information
Schedule
The full cohort
One continuous case across six Saturdays. Sessions build on each other, and each one can also be booked on its own.
- Sat 17 Oct 2026Foundations and the first alert10:30–13:30 ISTDetails →
- Sat 24 Oct 2026AI-era phishing and the initial foothold10:30–13:30 ISTDetails →
- Sat 31 Oct 2026Endpoint investigation and containment10:30–13:30 ISTYou are here
- Sat 7 Nov 2026Diwali holiday — no sessionNo session
- Sat 14 Nov 2026Cloud SOC and lateral movement10:30–13:30 ISTDetails →
- Sat 21 Nov 2026Detection engineering and automation10:30–13:30 ISTDetails →
- Sat 28 Nov 2026Immersive day and certification exam10:30–17:30 IST · full dayDetails →
Taking the whole cohort?
The six sessions are one continuous case, and the full course page carries the curriculum, the certification detail and the cohort pricing.

