Incident Response Process & Triage

intermediate Hands-on lab 35 min 3 tasksSubscription

Walk the NIST/PICERL incident-response lifecycle and perform first-responder triage of a compromised Windows host: where to look, what to collect, and how to spot a rogue process and persistence.

This lab is available with a Purple Edge subscription. Sign in to view the full overview and start the lab.

Part of these paths

Unlock this lab

Launch the lab in your browser. Real Kali, Ubuntu and Windows targets, guided step by step. No setup, no VM downloads.

Updated 2026-06-15