FAQ: Incident Response on Windows

This FAQ, collaboratively created by the community, addresses the contents of the course titled “Incident Response on Windows”.

This course includes these lessons:

  • How to Create Incident Response Plan?
  • Incident Response Procedure
  • 3 Important Things
  • Free Tools That Can Be Used
  • Live Memory Analysis - 1
  • Live Memory Analysis - 2
  • Users
  • Task Scheduler
  • Services
  • Registry Run Keys / Startup Folder
  • Files
  • Additional Solutions
  • Checklist

You can locate this exercise within the LetsDefend content:

hello i need help in Live Memory Analysis - 2

I couldn’t find it. Does anyone know?

Look at the Menu in Process Hacker. Navigate to View

Once in View —> Select Tray icon —> Select Network History
You should be able to access the information and view the file