What The Track Covers

Reasoning through a live host, not memorizing a checklist.

Every module is built around the same standard: an operator should be able to explain why something looks the way it does, not just recognize that it does.

Boot Sequence & Process Lineage

How a Windows host builds its process tree from power-on to desktop — and why an "orphaned" parent process is often expected behavior, not an anomaly.

Native Tooling First

Built-in Windows tooling and behavior before reaching for an automated wrapper around it — knowing the system underneath the shortcut.

Host Artifact Investigation

Reading path, parent, and user context together — the same triage judgment used to separate a real anomaly from a normal-but-unfamiliar pattern.

Interactive Resource

Practice building the process tree before you're on a live host.

A hands-on companion to this track: work through boot sequence questions, build a live multi-user process tree yourself, and practice spotting planted anomalies in randomly generated process lists.

Access — By Invitation

This resource is currently limited to invited students and training partners. If you already have access, continue below — you'll be asked to verify with your invited email. If you don't have access yet, reach out and we'll get you added.

Or email directly.

Want to see how this track fits into the full curriculum?