// Defense

Explore Incident Response

Detection isn't a signature match — it's noticing what legitimate-looking activity shouldn't be doing.

Incident response has a paperwork problem: plenty of organizations have a documented playbook and no practiced one. Nugget doesn't hand you a checklist and call it done — it puts you in the middle of a live incident and makes you decide, under the same ambiguity a SOC analyst gets, whether that anomalous PowerShell call is an admin doing their job or an attacker living off the land.

The sessions here track how real incidents actually run: containment, legal notification prep, and eradication happening at once, not in tidy sequence. You'll work through why the GDPR clock starts at 'became aware,' not 'investigation complete,' and why an IOC tells you something already happened while a behavioral pattern might catch it happening again. Nugget sketches the process tree, the log timeline, or the notification-deadline math on the whiteboard, then asks you to find where the story breaks.

This isn't a substitute for tabletop exercises or your incident response coursework — it's where you rehearse the reasoning between them, so the gap between your documented plan and your practiced one gets smaller.

// What a session feels like

You bring the questions. Nugget asks the next one.

  • Nugget lays out a snippet of process-tree data on the whiteboard — a parent process spawning something that shouldn't have legitimate reason to run — and asks you to explain why hunting for that relationship beats matching file hashes against a blocklist.
  • You're given a stored XSS report from a support ticket system: Nugget maps out how the payload reached an admin's session and asks you to trace where HTTPOnly would have blocked the exfiltration versus where it wouldn't have stopped the injection itself.
  • Nugget plots a timeline on the whiteboard — breach detected Tuesday, confirmed Thursday, notification drafted Friday — and pushes you to identify exactly where the 72-hour GDPR clock actually starts ticking, and why most teams get that date wrong.

Start exploring Incident Response tonight — a 30-day trial, cancel anytime.

Start your 30-day trial