The DFIR Report reposted this
Recently, after a great CTF from The DFIR Report at #misec's conference misecCON, I've been working through some of their DFIR Labs online DFIR training cases. Out of all of the online DFIR training platforms I've used, this has been my favorite. The cases include high-quality, realistic datasets leveraging a wide variety of different evidence sources loaded into a SIEM (Elastic or Splunk). The VMs have great performance and never lag. The price is very reasonable; I've been able to complete most cases in less than 2 days using Splunk (YMMV), which, at time of writing, costs a maximum of $25 for any of their cases. If you want a fun weekend project, pick up a DFIR Labs case based on a public report, work through the case, and reference the report for tips as you go. https://lnkd.in/gVRzZAUr #cybersecurity #dfir