What The Track Covers

Reasoning through a live host, not memorizing a checklist.

Every module is built around the same standard: an operator should be able to explain why something looks the way it does, not just recognize that it does.

Boot Sequence & Process Lineage

How a Windows host builds its process tree from power-on to desktop — and why an "orphaned" parent process is often expected behavior, not an anomaly.

Native Tooling First

Built-in Windows tooling and behavior before reaching for an automated wrapper around it — knowing the system underneath the shortcut.

Host Artifact Investigation

Reading path, parent, and user context together — the same triage judgment used to separate a real anomaly from a normal-but-unfamiliar pattern.

Interactive Resource

Practice building the process tree before you're on a live host.

A hands-on companion to this track: work through boot sequence questions, build a live multi-user process tree yourself, and practice spotting planted anomalies in randomly generated process lists.

Access — By Invitation

This resource is currently limited to invited students and training partners. If you already have access, continue below — you'll be asked to verify with your invited email. If you don't have access yet, reach out and we'll get you added.

Or email directly.

Reference Deck

Windows ProTips — SME/Mentor reference material.

A guided reference deck covering survey methodology, process carving, binary integrity checks, and a full Nix-to-Windows command cross-reference. View-only, viewable slide by slide in the browser.

Access — By Invitation

Same access model as the Boot Process Trainer above — limited to invited students and training partners. If you already have access, continue below.

Or email directly.

Want to see how this track fits into the full curriculum?