18 cards · Foundations, Practitioner, Applied, Advanced, Expert
Blue team / DFIR interview questions and practice topics
Blue team, detection and incident response (DFIR): triage, log sources, SIEM detections, memory and disk forensics, and talking through an incident while it is happening.
Each card is a topic to explain out loud against the clock: 10 are real interview questions, the rest are concepts, live incidents and deep dives. Open one to see what a strong answer covers, or open cardosec and pick Blue team / DFIR as a focus.
L1 Foundations What it is
L2 Practitioner How it works
- Alert TriageAn alert fires in the SIEM. How do you triage it?Explain · Interview
- Encoded PowerShell at 2amYou get an alert for encoded PowerShell launched by Excel at 2am. What do you do?Incident · Interview
- Evidence and Chain of CustodyExplain
- Key Windows Event IDsWhich Windows event IDs do you rely on most during an investigation?Explain · Interview
L3 Applied Abuse and defence in real systems
- Containment vs EradicationWhat is the difference between containment and eradication, and when do you contain?Explain · Interview
- How EDR WorksExplain
- Hypothesis-Driven Threat HuntingDeep dive
- Incident Response in the CloudDeep dive · Explain
- Memory ForensicsWhen and how would you do memory forensics on a compromised host?Explain · Interview · Deep dive
- Security Log Wiped on a DCIncident
- Someone Touched LSASSYou see LSASS memory access from rundll32 on a server. Walk me through your response.Incident · Interview
- Writing SIEM DetectionsHow do you write and maintain a good detection rule?Explain · Interview · Deep dive
L4 Advanced Edge cases, bypasses, trade-offs
L5 Expert Research-grade, architecture-level
Other domains
Web AppSec · Network · Identity & AD · Cloud · Cryptography · Malware & intel · Famous breaches · GRC · AI security