✅ Analyst 1 track + PWFA certification with distinction (challenge coin) ✅ Analyst 2 track incl advanced DFIR investigations Huge congratulations to Tim Coerlin for powering through both tracks and consistently showing high-quality work and real passion for DFIR. Love seeing pros who already do this for a living still choose to spend their evenings digging into new attacks and sharpening their investigation skills - that’s exactly who we build this training for. 🔥
Just wrapped up Blue Cape Security Analyst 2 – Advanced DFIR course. Thanks again, Markus Schober . Having already passed Analyst 1, which builds on this one, I finally dived into Analyst 2. You get hands-on with tools that actually matter in large-scale incidents and you test them right away in a lab that feels real. A little surprise: a short but spot-on peek behind the curtain of the Red Team planning. Didn’t expect that, really cool. The practice labs are on another level compared to Analyst 1. Way more data, way more artifacts to correlate. Proper timelines and IOC documentation suddenly become non-negotiable, exactly like in a real investigation. Huge respect for the insane amount of work that went into these scenarios. The IR300 lab with its fully simulated APT attacks was pure joy. So yeah… as someone who does DFIR for a living, spending my evenings on this does feel a bit like "work after work." But, honestly? It's pure fun! I get to examine and analyse both new and old attacker techiques, experiment with rarely used tools and actually feel my analytical skills getting sharper with every lab session. This is exactly the kind of “work” I’ll gladly stay up late for. (P.S. Still proud of this metal Challenge Coin from Analyst 1 PWFA Certification Exam – realy cool desk trophy🤘) Link to BlueCapeSecurity: https://lnkd.in/dU_a72Nb #DFIR #DigitalForensics #IncidentResponse #BlueCapeSecurity