<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Incident-Response on ku5e | Cybersecurity Portfolio</title><link>https://ku5e.com/tags/incident-response/</link><description>Recent content in Incident-Response on ku5e | Cybersecurity Portfolio</description><generator>Hugo -- 0.162.1</generator><language>en-us</language><lastBuildDate>Fri, 20 Mar 2026 16:29:00 +0000</lastBuildDate><atom:link href="https://ku5e.com/tags/incident-response/index.xml" rel="self" type="application/rss+xml"/><item><title>TryHackMe Rooms Are Not as Easy as They Feel</title><link>https://ku5e.com/blog/tryhackme-rooms-are-not-as-easy-as-they-feel/</link><pubDate>Fri, 20 Mar 2026 16:29:00 +0000</pubDate><guid>https://ku5e.com/blog/tryhackme-rooms-are-not-as-easy-as-they-feel/</guid><description>TryHackMe rooms feel easier than real incident response for a specific reason. Understanding that reason is what turns room practice into genuine readiness.</description></item><item><title>The First 90 Days in a Security Role Are Not on Any Cert Exam</title><link>https://ku5e.com/blog/the-first-90-days-in-a-security-role-are-not-on-any-cert-exam/</link><pubDate>Fri, 20 Mar 2026 16:25:00 +0000</pubDate><guid>https://ku5e.com/blog/the-first-90-days-in-a-security-role-are-not-on-any-cert-exam/</guid><description>Earning the cert gets you hired. What happens in the first 90 days is determined by two habits that no certification exam measures — and most candidates do not know which one they default to until it costs them.</description></item><item><title>TryHackMe: Threat Intel &amp; Containment</title><link>https://ku5e.com/blog/tryhackme-threat-intel-containment/</link><pubDate>Sun, 15 Mar 2026 20:59:00 +0000</pubDate><guid>https://ku5e.com/blog/tryhackme-threat-intel-containment/</guid><description>Walkthrough for the TryHackMe Threat Intel &amp;amp; Containment room covering threat intelligence creation, containment strategies, and basic Wireshark packet analysis.</description></item><item><title>TryHackMe: Tardigrade</title><link>https://ku5e.com/blog/tryhackme-tardigrade/</link><pubDate>Sun, 15 Mar 2026 20:53:00 +0000</pubDate><guid>https://ku5e.com/blog/tryhackme-tardigrade/</guid><description>TryHackMe Tardigrade walkthrough. Five persistence mechanisms on a compromised Linux server, from bashrc alias hijacking to abused system accounts.</description></item><item><title>TryHackMe: Preparation</title><link>https://ku5e.com/blog/tryhackme-preparation/</link><pubDate>Sun, 15 Mar 2026 20:31:00 +0000</pubDate><guid>https://ku5e.com/blog/tryhackme-preparation/</guid><description>TryHackMe walkthrough for the Preparation phase of incident response — building a CSIRT, defining roles, establishing log management pipelines, and configuring Windows Event Log collection before an incident occurs.</description></item><item><title>TryHackMe: Identification &amp; Scoping</title><link>https://ku5e.com/blog/tryhackme-identification-scoping/</link><pubDate>Sun, 15 Mar 2026 20:29:00 +0000</pubDate><guid>https://ku5e.com/blog/tryhackme-identification-scoping/</guid><description>TryHackMe walkthrough for Identification and Scoping — determining what systems were affected, mapping phishing indicators, and building the initial picture of a live incident before containment begins.</description></item><item><title>TryHackMe: Eradication and Remediation</title><link>https://ku5e.com/blog/tryhackme-eradication-and-remediation/</link><pubDate>Sun, 15 Mar 2026 20:22:00 +0000</pubDate><guid>https://ku5e.com/blog/tryhackme-eradication-and-remediation/</guid><description>TryHackMe walkthrough covering eradication and remediation in incident response — removing attacker persistence, patching exploited systems, and restoring operations using MITRE ATT&amp;amp;CK and Jenkins-based tooling.</description></item></channel></rss>