// digital forensics & incident response · video series

week x of dfir
lab walkthroughs

Every week CyberDefenders and BTLO retire a lab — I record a full walkthrough. Retired labs only, so solutions are public and every question gets answered on camera. Static & dynamic malware analysis, memory forensics, network PCAP investigation — level 2 DFIR skills documented publicly.

8
Episodes
RETIRED
Labs Only
CCD × BTLO
Platforms
CYBERDEFENDERS × INKSEC.IO · WEEK X OF DFIR
ContainerBreak - Rootkit Trail thumbnail
CYBERDEFENDERS × INKSEC.IO
WEEK 07 OF DFIR
PLATFORM: CYBERDEFENDERS
CATEGORY: [Endpoint Forensics]
DFIR SERIES // [ENDPOINT FORENSICS] // CYBERDEFENDERS
ContainerBreak - Rootkit Trail
Investigated a post-container-escape Linux compromise involving rootkit installation, hidden processes, and persistence mechanisms identified through live forensic collection.
Tools
Linux Command Line Tools
Tactics
ExecutionPersistencePrivilege Escalation
Stolen Time - HiddenTear thumbnail
CYBERDEFENDERS × INKSEC.IO
WEEK 06 OF DFIR
PLATFORM: CYBERDEFENDERS
CATEGORY: Threat Hunting
DFIR SERIES // THREAT HUNTING // CYBERDEFENDERS
Stolen Time - HiddenTear
Multi-host Splunk and KAPE investigation reconstructing a HiddenTear ransomware intrusion from a pirated-software download through Cobalt Strike C2, Golden Ticket forging, and cross-server lateral movement to domain-wide encryption.
Tools
DB Browser for SQLiteRegistry ExplorerTimeline ExplorerSplunk
Tactics
ExecutionPersistencePrivilege Escalation
Spooler - APT28 thumbnail
CYBERDEFENDERS × INKSEC.IO
WEEK 05 OF DFIR
PLATFORM: CYBERDEFENDERS
CATEGORY: Endpoint Forensics
DFIR SERIES // ENDPOINT FORENSICS // CYBERDEFENDERS
Spooler - APT28
Trace an APT28 intrusion from a trojanized HR archive through mshta.exe remote HTA execution, certutil LOLBin download, DLL sideloading, dual-layer Print Spooler and Run key persistence, and AlwaysInstallElevated SYSTEM escalation.
Tools
Registry ExplorerDB Browser for SQLitePECmdMFTECmd
Tactics
Initial AccessExecutionDefense Evasion
KioskExpo7 thumbnail
CYBERDEFENDERS × INKSEC.IO
WEEK 04 OF DFIR
PLATFORM: CYBERDEFENDERS
CATEGORY: Endpoint Forensics
DFIR SERIES // ENDPOINT FORENSICS // CYBERDEFENDERS
KioskExpo7
Analyse a KAPE triage image from a compromised conference kiosk to reconstruct a physical access attack chain from browser kiosk breakout through privilege escalation, credential theft, persistence via scheduled tasks, and attendee-targeting QR code swap.
Tools
CyberChefDB Browser for SQLiteEZ ToolsDCode
Tactics
Initial AccessExecutionPersistence
Maranhao Lab thumbnail
CYBERDEFENDERS × INKSEC.IO
WEEK 03 OF DFIR
PLATFORM: CYBERDEFENDERS
CATEGORY: Endpoint Forensics
DFIR SERIES // ENDPOINT FORENSICS // CYBERDEFENDERS
Maranhao Lab
Investigate a trojanized game installer by analyzing browser history, logs, registry hives, and filesystem artifacts to map the full attack chain and extract IOCs.
Tools
FTK Imager
Tactics
Initial AccessExecutionPersistence
MBuchus thumbnail
CYBERDEFENDERS × INKSEC.IO
WEEK 02 OF DFIR
PLATFORM: CYBERDEFENDERS
CATEGORY: [Threat Intel]
DFIR SERIES // [THREAT INTEL] // CYBERDEFENDERS
MBuchus
Utilize OSINT, VirusTotal, and crt.sh to analyze a multi-stage malvertising campaign, identifying initial access, malware payloads, and attacker infrastructure.
Tools
OSINTVirusTotal
Tactics
Resource DevelopmentCommand and Control
Revenge Hotels APT thumbnail
CYBERDEFENDERS × INKSEC.IO
WEEK 02 OF DFIR
PLATFORM: CYBERDEFENDERS
CATEGORY: Endpoint Forensics
DFIR SERIES // ENDPOINT FORENSICS // CYBERDEFENDERS
Revenge Hotels APT
Reconstruct a multi-stage RevengeHotels APT intrusion by correlating Chrome browser history, Sysmon event logs, registry artifacts, and .NET malware analysis to trace the full attack chain from phishing JS dropper through Quasar RAT persistence and data exfiltration.
Tools
CyberChefDB Browser for SQLitednSpyWindows Event Viewer
Tactics
Initial AccessPersistencePrivilege Escalation
XWorm thumbnail
CYBERDEFENDERS × INKSEC.IO
WEEK 01 OF DFIR
PLATFORM: CYBERDEFENDERS
CATEGORY: Malware Analysis
DFIR SERIES // MALWARE ANALYSIS // CYBERDEFENDERS
XWorm
Analyze malware behavior to identify persistence methods, evasion techniques, and C2 infrastructure by extracting artifacts and configuration data from static and dynamic analysis.
Tools
PEStudiodnSpy
Tactics
ExecutionPersistencePrivilege Escalation