What problem does it solve? Preparing for the OffSec IR-200 (OSIR) certification requires mastering the full incident response lifecycle, Splunk SPL detection queries, disk and memory forensics, and structured post-mortem reporting, and this Skill consolidates all of that guidance in one place. ## Core Features & Use Cases - Splunk SIEM Detection Queries: Ready-to-use SPL queries for brute force, lateral movement, persistence, Kerberoasting, and C2 detection across Windows Event Logs and Sysmon. - Digital Forensics Workflows: Step-by-step Autopsy disk analysis and Volatility 3 memory analysis commands, including malfind, psscan, and netscan usage. - Exam Strategy & Reporting: 8-hour time management plan, scoring breakdown (50/70 to pass), report templates, chain of custody tables, and regulatory notification checklists (GDPR, HIPAA, SEC). - Use Case: During an OSIR practice lab, ask for the SPL query to detect pass-the-hash activity, then get the Volatility 3 commands to confirm process injection on the compromised host. ## Quick Start Ask the agent to walk you through investigating a suspected ransomware incident using Splunk logs and a memory dump following the OSIR exam methodology.