Security Notes
Study tracks

Incident Responder Interview Track

Ten focused days for a security incident-response or detection-engineering loop. Each day has a theme; Core items are what an IR interviewer will probe, the rest earn bonus points. Tick an item only once you can answer its questions out loud in about a minute.

3 min read 10 sections

Day 1 — Detection engineering

Day 2 — Endpoint, hunting and identity detection

Day 3 — Incident response craft

Day 4 — Forensics and malware triage

Day 5 — Windows and Active Directory

Day 6 — Linux defence and privilege escalation

Day 7 — Cloud incident response

Day 8 — Kubernetes and networking

Day 9 — Identity, crypto, web and supply chain

Day 10 — Behavioural, breadth and mock interviews