Reading width
Wide uses the full column for everything, text, diagrams, code, and exercises. Narrow keeps the standard reading width.
Text size
Scales the body text. Headings and code blocks keep their size.
In this section
Module Summary
What this module covered
0.1 set out the proposition. Most investigative tools answer questions about evidence you already hold; this one changes which problem you have, because an agent on the endpoint answers from the live system and nothing had to be shipped in advance. The important change is not speed but which questions are worth asking, since a question costing ten seconds rather than a day gets asked on a hunch. One condition is absolute: the agent has to have been there before the incident, which is why deployment is treated as the capability rather than as an install step.
0.2 mapped the course. Seven modules in the order the work happens, with the order load-bearing rather than conventional: a hunt is a collection multiplied, a hunt result is read with queries, and containment needs an account of what it is containing. Every teaching section has the same shape, opening with a specific failure and closing with one paragraph to carry, and the knowledge checks are built so that wrong answers are the reasoning a competent practitioner offers.
0.3 described the environment. One binary, no license, nothing gated, so the lab this course assumes can be built without asking anybody for anything. Northgate Engineering is the fictional estate throughout, and its details are load-bearing: the service account, the deployment tool, the laptops and the imperfect inventory each carry a section later. The examples are real artifact names, runnable queries and representative output, with interface screens drawn rather than photographed.
0.4 covered where the capability shows up. Incident response on machines you cannot reach, where the unglamorous majority of the value is the alerts that stop consuming an afternoon each. Hunting, where a small team gets leverage that cuts both ways. Proactive work, whose real obstacle is that it pays nothing on the day you do it. And supporting an investigation somebody else owns, which is the case where your process is what gets judged.
0.5 stated the limits first. The machines the agent never reaches, which are disproportionately where a foothold survives. The volatile deadline you can beat and the retention horizon you cannot. The questions that live in network, service or directory records rather than on the host. And the category the course spends most of its time on, which is the assumptions the interface lets you keep, because this platform is deliberately tolerant and the price of that tolerance is that judgment another tool would enforce is left to you.
0.6 got you running. A single command for a working deployment, the lab additions in the order the course needs them, and four habits worth having from the first collection rather than the fiftieth: read the state before the rows, write down why, form a row expectation, and name the clock.
What's next
Module 1 makes the deployment real. What the tool reaches and what it never will, the architecture behind a two-second answer, choosing a deployment model and standing up a server, the roles that decide who can do what, and enrolling clients so that the fleet in your console describes something true.
It is the module that decides whether everything after it is possible, and the first section is about the gap between the estate you have and the estate your console shows you.
How was this module?
Your feedback helps us improve the course. One click is enough, comments are optional.