Study tracks
Incident Responder Interview Track
Ten focused days for a security incident-response or detection-engineering loop. Each day has a theme; Core items are what an IR interviewer will probe, the rest earn bonus points. Tick an item only once you can answer its questions out loud in about a minute.
3 min read
10 sections
Day 1 — Detection engineering
- Core Detection engineering — lifecycle, detection-as-code, Sigma/SPL/KQL, ATT&CK coverage, Pyramid of Pain
- Core SIEM log pipeline — collect → parse → normalise → enrich → store, OCSF/ECS
- Core Known-good processes — know normal, find evil; masquerade red flags
Day 2 — Endpoint, hunting and identity detection
- Core Endpoint detection — how EDR works, process trees, Sysmon, auditd/eBPF, macOS ESF
- Core Threat hunting — hypothesis-driven hunts, beaconing, hunts → detections
- Identity threat detection — MFA fatigue, token theft, OAuth abuse, Golden SAML
Day 3 — Incident response craft
- Core IR psychology — OODA, dwell time, biases, SBAR
- Core Phishing triage — what to check per channel, blast radius, response
- Core Analyst OPSEC — VirusTotal uploads, tipping off the adversary, evidence
- Core Reports and postmortems — RCA, 5 Whys, writing per audience
Day 4 — Forensics and malware triage
- Core Digital forensics — order of volatility, acquisition, Volatility 3, timelines, chain of custody
- Core Linux reverse engineering — ELF triage, strace/ltrace, IOC extraction, YARA
- EDR evasion — injection, unhooking, AMSI/ETW bypass, BYOVD
- Anti-debugging — PEB flags, timing checks, TLS callbacks, API hashing
Day 5 — Windows and Active Directory
- Core Active Directory attacks — NTLM relay, LSASS, DCSync, Golden/Silver Ticket
- Core Windows registry — persistence keys, SAM/LSA, ShimCache/AmCache
Day 6 — Linux defence and privilege escalation
- Core Linux security fundamentals — Secure Boot, SELinux/AppArmor, seccomp, auditd
- Core Linux privilege escalation — SUID, sudo, cron, capabilities, container escape
- Production deployment security — SSH access, least-privilege services, patching
- Linux hardening — sysctl, SSH, AIDE
Day 7 — Cloud incident response
- Core AWS IAM deep dive — roles, policy evaluation, IMDS/IRSA, leaked-key response
- Core AWS incident response — EC2, EKS pod, S3, Lambda, credential playbooks
- AWS fundamentals — VPC, KMS, S3, EC2, Lambda and their gotchas
- GCP incident response — SCC triage, GKE IR
Day 8 — Kubernetes and networking
- Core Kubernetes incident response — container forensics, isolation, containment
- Core DNS deep dive — resolution, email auth, tunnelling, rebinding
- Kubernetes security — RBAC, Pod Security Standards, admission control, Falco
- tcpdump, eBPF and the TCP stack — BPF filters, packet dissection
- HTTP/HTTPS deep dive — HTTP/2 rapid reset, headers, cookies
Day 9 — Identity, crypto, web and supply chain
- Core Authentication deep dive — OAuth + PKCE, JWT attacks, passkeys, Kerberoasting
- Cryptography — hashing for IOCs, encoding vs encryption, ransomware crypto
- AppSec deep dive — OWASP Top 10, SSRF, deserialisation
- GitHub and CI/CD security — Actions hardening, poisoned pipelines, OIDC
- OWASP LLM Top 10 — prompt injection, excessive agency
Day 10 — Behavioural, breadth and mock interviews
- Core Behavioural answers — STAR stories for the common questions
- Core Breadth notes — one fast end-to-end skim
- Compliance frameworks — SOC 2, ISO 27001, PCI-DSS, NIST CSF talking points
- Questions to ask the interviewer — the close
- Core Mock round 1 — detection and IR scenarios, out loud and timed
- Core Mock round 2 — revisit every Core item still unticked