Suspicious PowerShell investigation
Available nowLive case: alert triage, process analysis, terminal, KQL, notes, report.
Beginner path
FirstShift teaches investigation by working alerts, reading evidence, practicing with guided tools, and writing notes the way an analyst would on shift.
You open a case, inspect evidence, run commands and queries in a safe fixture environment, capture notes, and submit a report. Grading runs server-side against the scenario configuration.
Live case: alert triage, process analysis, terminal, KQL, notes, report.
Concepts that frame the first investigation.
Planned modules; not available in the workspace yet.
Planned modules; not available in the workspace yet.
Planned modules; not available in the workspace yet.
More scaffolding and hints while you learn the investigation loop.
You lead; support appears when you request it.
Minimal guidance. Full ownership of tools and documentation.
Plan roughly 45–90 minutes for Suspicious PowerShell depending on mode. You produce notebook entries, a disposition, and a graded report tied to the attempt.