Stop learning about investigations. Learn how to investigate.
When someone asks you to walk them through how you would investigate a scenario, can you explain what you would do, why you would do it, and defend your decisions?
Six weeks of investigations, direct feedback, challenged reasoning and reporting. Every week you progress from an example investigation, to a guided investigation, to a case you own and defend.
A few quick questions when you book, so I know where you are before we talk.
I am only accepting a maximum of 30 people, because I need to personally review your work, question your reasoning, and give meaningful feedback.
Work through investigations where you decide what to do next.
Direct feedback on your reasoning, scope, findings, and conclusions.
Turn your investigation into a clear, defensible report.
Explain each decision and the evidence behind your conclusion.
"Walk me through how you would investigate this."
You cannot control how difficult the job market is, or who else is in the room.
You can control how prepared you are when someone finally gives you the opportunity.
You have learned cybersecurity. Now can you show how you investigate?
You do not need another list of things to study.
I remove the unnecessary friction. You focus on the investigation.
Everything in the cohort comes back to the same three responsibilities.
Set the objective, ask the right questions, follow the evidence, scope what happened, and reach a conclusion the evidence supports.
Turn the investigation into a clear account of what happened, what you concluded, what you cannot conclude, and why it matters.
Explain your decisions, answer questions about your scope and evidence, and stand behind what the evidence supports.
InvestigateReportDefend
Every week runs the same way.
We walk through a realistic case using the investigation framework so you can see how the objective, questions, evidence, pivots, scope, and conclusion fit together.
We tackle the alert together in the console. You follow along in your own environment while we decide what questions to answer, where to look next, what to pivot on, and what the evidence supports.
You take ownership of a new alert with no walkthrough telling you what comes next. You investigate it yourself, write the report, and defend your conclusion.
ExampleGuidedIndependent
Each week, we walk through the framework, tackle an alert together, then you apply it independently. As the cohort progresses I expect more from your reasoning and give you less to lean on.
Across six weeks you will investigate scenarios spanning Email, Endpoint, Identity, Active Directory, Cloud, Linux, and more.
You will investigate.
You will make decisions.
You will get stuck.
I will challenge your reasoning.
You will get direct feedback.
You will write and defend your findings.
I will expect more from you every week.
The goal is not to memorize the right answer. It is to learn how to find it.
A purpose-built business environment where the users, systems and telemetry carry across your investigations, with scenarios built to make you investigate instead of follow instructions.
Meaningful feedback on your reasoning, scope, evidence, reports, and conclusions.
Turn findings into clear reports that expose the gaps in your own reasoning.
Be questioned on what you decided, why you stopped, and what could change your conclusion.
Confidence from repeatedly proving you can work an investigation, not from being told to feel it.
Keep the reports and capstone work you produce so you can speak to your investigation process, decisions, and growth.
From members I have trained. The First Investigation Cohort will begin on November 7th.
"Working through alerts, building queries, correlating logs, mapping activity to MITRE ATT&CK, and documenting findings has helped me understand how the pieces fit together in an investigation. It has also gotten me a lot better at knowing what to investigate next instead of just staring at a bunch of logs and hoping something jumps out."
Nigel D.MYDFIR Member
"Steven helped me put all this theoretical knowledge and labs together to truly understand what happens behind the hood and how to build an investigation."
David G."I didn't know how to triage or investigate an alert before. Now I'm fairly confident triaging and investigating an alert using Splunk or Sentinel and providing a report."
Srinivas G.
I have spent over a decade in cybersecurity, mainly across security operations and DFIR.
When I started as a Tier 1 SOC analyst I got very little training, and I constantly questioned whether I was investigating things correctly.
I turned down an opportunity to move up because I did not trust my own investigative ability.
Over time I put in the reps, learned from mistakes, trained other analysts, and became someone who could step into a situation and work through the evidence.
This cohort is built around the deliberate practice, scrutiny, and feedback I wish I had early on.
For aspiring and current SOC analysts who already have some cybersecurity foundation and are ready to focus specifically on becoming stronger investigators.
A short call to work out whether the cohort solves the problem you actually have. If it does not, I will tell you.
I open my calendar 7 days at a time, and spots fill up fast. A new day opens every morning, so more times are always coming. If you don't see one that works today, set a reminder on your phone and check back tomorrow.
Enrollment closes November 1. Booking a call does not mean you have been accepted into the cohort. I read your answers beforehand, and if it is clearly not the right fit I will let you know before the call so we do not waste your time.
No. My calendar only shows the next 7 days, so it is not a waitlist and it is not sold out. Times get booked quickly, but a new day opens every morning.
Check back tomorrow and you should see fresh times. Enrollment closes November 1, so there is still room before then.
Onboarding week runs November 1 to 6. Enrollment closes November 1 and your access opens the same day, so that week is for prerequisites, environment access and setup checks. Nobody loses a training session to setup problems.
Live training runs November 7 to December 13. Six weeks.
Live training begins Saturday November 7 and runs six weeks. Sessions are Saturday and Sunday, 9am to 2pm Eastern, and I extend the hours when a session needs it. Wednesdays are live report reviews and defenses on the work you submitted that week.
Training weekends are Nov 7/8, 14/15, 21/22, 28/29, Dec 5/6 and 12/13.
Week 6 is your capstone investigation.
On top of the live sessions you work investigations between them. That is where most of the learning happens, so if you are not going to do that work you will not get much out of this.
Everything is hosted in Eastern Time. Sessions run 9am to 2pm ET, which works comfortably across the Americas, the UK, Europe, Africa and the Middle East.
If you are in Asia or Oceania it will be late at night or overnight your time. I would rather you knew that before you book than find out on the call.
No. What matters is that you have done enough learning that investigation ability is now the thing holding you back.
No. All you need is a browser and an internet connection.
It can be. Plenty of working analysts can run a process but want to get sharper on scoping, timelines, reporting, and holding their position when someone questions the finding.
Sessions are recorded so you can catch up on the content. Your report review and defense happen live, which is why attendance matters.
Yes and no. Every investigation you conduct except for the capstone, you may add to your portfolio and share them on LinkedIn!
You cannot control the job market.
You cannot control who else applies.
You cannot control when your next opportunity comes.
You can control how prepared you are when it does.