Join me as I solve the WorkFromHome lab on CyberDefenders! This challenge is a
great hands-on exercise for anyone learning Windows digital forensics or blue
team investigation techniques.
In this walkthrough, we go step by step through:
🌐 Browser Artifacts — uncovering web activity left behind
🖥️ AnyDesk Artifacts — tracing remote access sessions
⚡ Prefetch Files — identifying program execution
📋 USN Journal — tracking file system changes
🗂️ MFT (Master File Table) — deep file system analysis
📝 Windows Event Logs — piecing together the timeline
Perfect for SOC analysts, DFIR beginners, or anyone prepping for
certifications like BTL1, GCFE, or CCD.
⏱️ Timestamps:
00:00 Introduction
01:38 Scenario Introduction and Context
06:06 Initial Access - Question 1
11:58 C2 - Question 2
14:41 Discover - Question 3
16:17 Discover - Question 4
19:21 Discover - Question 5
20:23 Exfiltration - Question 6
21:36 Credential Access - Question 7
28:33 Credential Access - Question 8
30:27 Privilege Escalation - Question 9
32:12 Privilege Escalation - Question 10
39:34 Privilege Escalation - Question 11
47:45 Privilege Escalation - Question 12
54:38 Privilege Escalation - Question 13
56:37 Defense Evasion - Question 14
01:01:10 Persistence - Question 15
🔗 https://cyberdefenders.org/blueteam-c...
🔔 Subscribe for more CyberDefenders walkthroughs, CTF solutions, and cybersecurity content!