-
Collect and validate digital forensic evidence
Assessment Strategies
Skill Demonstration and/or Written Product
Criteria
Acquire or export forensic data using methods appropriate to the evidence source
Verify evidence integrity using cryptographic hashes when applicable
Preserve original evidence while conducting analysis on working copies
Document evidence sources and collection actions sufficiently to support repeatability
-
Analyze packet capture data using command-line tools
Assessment Strategies
Skill Demonstration and/or Written Product
Criteria
Extract capture metadata including time range, packet counts, hosts, and protocols
Filter PCAP data using protocol, host, port, field, or content criteria
Extract focused packet sets or transaction data for further analysis
Interpret command output to identify activity relevant to an investigation
-
Analyze network traffic using graphical forensic tools
Assessment Strategies
Skill Demonstration and/or Written Product
Criteria
Use Wireshark, NetworkMiner, or equivalent tools to examine sessions and transferred content
Identify hosts, users, domains, files, and protocols represented in network evidence
Reconstruct relevant conversations or application transactions
Identify anomalous or malicious behavior from network evidence
-
Analyze security monitoring data for threat hunting
Assessment Strategies
Skill Demonstration and/or Scenario Response
Criteria
Query Security Onion or equivalent monitoring data for events of interest
Use alerts, network metadata, and endpoint telemetry to develop investigative leads
Pivot between related events using fields such as IP address, domain, filename, Community ID, or process identifier
Refine searches to test investigative hypotheses
-
Analyze Windows event log evidence
Assessment Strategies
Skill Demonstration and/or Written Product
Criteria
Identify Windows event sources relevant to authentication, account, process, and system activity
Interpret event fields and identifiers within the context of an investigation
Correlate related events across users, hosts, logon sessions, or timestamps
Identify patterns consistent with failed access, privilege changes, lateral movement, or other suspicious activity
-
Analyze Windows file system and execution artifacts
Assessment Strategies
Skill Demonstration and/or Written Product
Criteria
Extract and interpret forensic metadata from Windows artifacts
Use artifacts such as LNK files, Prefetch, or related execution evidence to reconstruct user or process activity
Correlate artifact timestamps and paths with other investigative evidence
Identify artifacts that persist after files or folders have been modified or removed
-
Analyze registry and browser artifacts
Assessment Strategies
Skill Demonstration and/or Written Product
Criteria
Locate registry or browser artifacts relevant to user and system activity
Interpret artifact fields, timestamps, paths, URLs, or configuration data
Correlate registry and browser findings with file system, log, or network evidence
Identify evidence of persistence, downloads, browsing activity, or other actions relevant to an investigation
-
Correlate multi-source evidence to reconstruct attack activity
Assessment Strategies
Case Study and/or Report
Criteria
Combine PCAP, event log, endpoint, and forensic artifact evidence into a chronological sequence
Identify relationships among hosts, users, processes, files, domains, and network connections
Use MITRE ATT&CK or equivalent models to organize observed adversary behavior
Revise investigative hypotheses as supporting or contradictory evidence is discovered
Limit conclusions to claims supported by the available evidence
-
Conduct hypothesis-driven threat hunting
Assessment Strategies
Scenario Response and/or Project
Criteria
Formulate a testable hypothesis from an alert, anomaly, indicator, or known adversary behavior
Select data sources and queries appropriate to the hypothesis
Evaluate evidence that supports or disproves the hypothesis
Identify additional evidence needed to increase confidence in findings
Document the investigative path and resulting conclusions
-
Produce professional forensic investigation documentation
Assessment Strategies
Report and/or Presentation
Criteria
Document the environment, affected systems, and evidence sources
Create a clear timeline of significant investigative events
Record indicators of compromise and supporting technical evidence
Distinguish confirmed findings from assumptions and unresolved questions
Communicate findings and implications clearly to technical and non-technical audiences