ogmini - Exploration of DFIR

Having fun while learning about and pivoting into the world of DFIR.


About Blog Posts by Tags Research Talks/Presentations GitHub Search RSS
23 September 2026

CISA IR Training - Ransomware Threat Hunting Workshop (IR309)

by ogmini

Just finished “Ransomware Threat Hunting Workshop (IR309)” offered by CISA in coordination with Cybervance. I talked about these in a previous post and would encourage those eligible to register.

This was a great course! We were broken up into teams and set loose to investigate a ransomware incident. The instructors provided a Threat Advisory with some IOCs and an email was sent to the team from a fake user reporting a suspicious document they received by email. From there, we had to go hunting to find the all the stages from inital email phishing to ransomware execution. After detection and analysis, we had to pivot to containment, eradication, and recovery. Finally culminating in a report.

We utilized:

  • Microsoft Sentinel - for hunting
  • Velociraptor - for hunting and eradication
  • TheHive - for recording
  • Palo Alto NGFW - for firewall blocking

I won’t go into specifics about the scenario as they might re-use it in the future. No answers for you!

Thoughts

This was a great course and my only suggestion would be to add voice communications for the teams. We were only able to chat and I found that to be very constraining. I think I know why they chose to do this as it allowed the instructor to easily peek into our conversations and make observations about how we worked.

I had a few personal takeaways from this course which highlighted some areas of improvement and wins. Firstly, it is hard to work with a team that you’ve never worked with before. You don’t know everyone’s personalities or backgrounds and how to mesh with them. We had 0 time to get to know each other before being thrust into the scenario. I learned that is important for someone/anyone to take the lead and assign roles. In my professional life, I’m very used to working solo due to resource constraints and it shows. This is a gap that needs to be worked on. Again, voice communications might have made introductions easier.

Knowing your toolset and environment makes things so much easier. When I read the Threat Advisory, I knew exactly what I had to mechanically do IF I was at work in our environment. It took me probably a good 30 minutes to get my bearings of the simulation environment, what I had access to, what data was available to me, and how to query it. I have more tools at my disposal at work that make certain hunting easier and faster.

I feel a lot more confident with my ability to write KQL queries and use Velociraptor. Simulations like these help to flex and exercise those skills. I have a few goto KQL queries in our environment and this course forced me to go outside that comfort space.

Documentation, Documenation, Documentation! What more needs to be said? I consider this a weakness as I have a habit of going headfirst into investigations and document afterwards. This is incredibly hard and you tend to miss/forget actions you might have taken. Using a tool like TheHive helps incredibly with recording. I want to investigate that tool a little more and see how it might be assist.

Finally, I believe we were the only team to identify all 7 IOCs and remediate all 5 issues. That was a great accomplishment and gives me confidence in my abilities.

I really hope that CISA/Cybervance does more of these types of advanced courses. It would be really cool if they did one of these in-person as the dynamic of working an incident would be changed drastically.

tags: #Training