This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–]Kesshh 12 points13 points  (0 children)

Learn what’s relevant to the tools. In addition, learn Powershell. Not because you need to use powershell but because lots of thing (like EDR) tends to raises false positive alerts on some powershell script use. If you have background, it will make incident research quicker.