Incident Analysis: Collection & Exfiltration
In this hands-on lab, you will learn how to analyze common collection mechanisms during an incident response engagement.

Course Content
Upon completing this lab, you should be able to:
- List and describe selected common methods of Collection and Exfiltration associated with Windows environments.
- Develop and test hypotheses relevant to Collection and Exfiltration observations.
- Describe how generic analytical methods can be applied to the examination of Collection and Exfiltration activity.
- Examine example evidence of the Collection techniques T1560.001 Archive via Utility and T1074 Data Staged.
- Examine example evidence of the Exfiltration technique T1537 Transfer to Cloud Account.
- Document different Collection and Exfiltration findings.













