CDSA validates practical blue-team skills across SOC triage, threat hunting, and incident response reporting. 2026 prep should prioritize query fluency, investigation timelines, and decision justification.
Official PageMemory forensics and process-level investigation.
pipx install volatility3vol -f mem.raw windows.pslistSearch and correlation for SOC triage workflows.
index=* | stats count by sourcetypeDetection rule conversion and validation.
pipx install sigma-clisigma convert -t splunk rule.ymlEndpoint artifact collection and rapid response.
velociraptor query artifactsPacket analysis for incident reconstruction.
sudo apt install -y wiresharkwireshark capture.pcapConsistent HTB exam-like tooling baseline.
Maintain reusable aliases and workflow scriptsCollaborative timeline analysis for incidents.
timesketch