CODE BLUE 2026 Training Description

Title


English Description

Overview

This 3-day hands-on training teaches you how to investigate Windows compromises using free and open-source tools — and how to supercharge that analysis with generative AI. It is a major upgrade of the 2-day training held at CODE BLUE last year, expanded with new sections on evidence acquisition, popular Windows forensic artifacts (Master Boot Record, Prefetch, Shimcache, and more), using AI to create Sigma detection rules, and automatically analyzing Hayabusa results with AI.

Format: Hybrid & Self-Paced ("Choose Your Own Adventure")

The training is offered both in person and online. The core material is delivered through pre-recorded lecture videos that you watch at your own pace (please bring headphones). We adopted this format because students' skill levels vary widely — this way, experienced analysts can skip ahead or jump straight into the hands-on CTF, while those who prefer a structured approach can work through the lectures first. You choose your own path.

Why attend in person? We recommend in-person attendance if you think you may need troubleshooting help or want to ask lots of questions. In-person attendees also get to work in teams for the CTF and final presentation, and an award will be given to the best team presenting in person.

Language

The training materials, lecture videos, and the lecture introduction are all provided in both Japanese and English. However, please note that the real-time (live) portions of the training will be conducted mostly in Japanese, unless there are enough English-only speakers in attendance. If there are not enough English-only speakers to form a team, English-only attendees will work through the CTF analysis individually. (Presenting is optional.)

What's Included

Returning Students

If you attended last year's training, you can attend this year's full 3-day training online for ¥100,000 and get access to all new and updated material. (The CODE BLUE conference ticket is not included in this discounted option.)

Instructor

Zach Mathis — Project leader of Yamato Security. Zach has been doing information security for over 30 years and leads the Yamato Security organization, which has been releasing free and open-source forensics tools together with its members since 2020. These tools are used daily around the world for incident response and digital forensics.

Topics Covered

Foundations: Windows Event Log Analysis

Audit Policy & Log Configuration (Preparation Before an Incident)

Sysmon

Evidence Acquisition

🆕 Windows Forensic Artifacts (New for 2026)

Yamato Security Tools

Deep-Dive: Critical Logs

Sigma Rule Creation

Detecting Common Active Directory Attacks

Anti-Forensics Techniques and Countermeasures

Scaling Up & AI

CTF & Final Presentations


Japanese Description(日本語)

概要

本トレーニングは、フリーかつオープンソースのツールを駆使してWindows侵害調査を行う方法を、3日間のハンズオン形式で徹底的に学ぶコースです。さらに、生成AIを活用して解析を高速化・自動化する最新手法も扱います。昨年CODE BLUEで実施した2日間トレーニングを大幅にアップグレードし、証拠保全(エビデンス取得)、Master Boot Record・Prefetch・Shimcacheなどの主要なWindowsフォレンジックアーティファクト、生成AIによるSigmaルール作成、AIによるHayabusa解析結果の自動分析といった新セクションを追加しました。

形式:ハイブリッド開催&自分のペースで進める「Choose Your Own Adventure」型

本トレーニングは現地参加・オンライン参加のどちらでも受講可能です。講義は事前収録ビデオを各自のペースで視聴する形式で進めます(ヘッドホンをご持参ください)。この形式を採用した理由は、受講者のレベルが大きく異なるためです。経験者は既知のセクションをスキップしてすぐCTF(ハンズオン演習)に挑戦でき、じっくり学びたい方は講義から順番に進められます。進め方はあなた次第です。

現地参加をおすすめする方: トラブルシューティングのサポートが必要になりそうな方や、講師にたくさん質問したい方には現地参加をおすすめします。また、現地参加者はCTFと最終発表をチームで取り組むことができ、現地で発表した最優秀チームには賞を授与します。

言語について

トレーニング資料、講義ビデオ、および講義のイントロダクションは日本語・英語の両方で提供されます。ただし、リアルタイム(ライブ)で実施する部分は、英語のみ話す受講者が一定数いない限り、主に日本語で行われますのでご了承ください。英語のみ話す受講者がチームを組めるほど集まらなかった場合は、CTF解析は個人で取り組んでいただきます。(発表は任意です。)

受講に含まれるもの

昨年の受講者向け特別価格

昨年のトレーニングを受講された方は、今年の3日間トレーニングをオンライン受講10万円でご参加いただけます。新規・更新されたすべての教材にアクセスできます。(※この特別価格にはCODE BLUEカンファレンスチケットは含まれません)

講師

Zach Mathis(マシス・ザック) — Yamato Securityプロジェクトリーダー。30年以上にわたり情報セキュリティに携わり、2020年からメンバーとともにフリー&オープンソースのフォレンジックツールを公開してきた大和セキュリティを率いる。これらのツールは世界中でインシデント対応やデジタルフォレンジックの現場で日々活用されている。

カバーするトピック

基礎:Windowsイベントログ解析

監査ポリシーとログ設定(インシデント前の事前準備)

Sysmon

証拠保全(エビデンス取得)

🆕 Windowsフォレンジックアーティファクト(2026年新設)

大和セキュリティツール

重要ログの深掘り

Sigmaルール作成

よくあるActive Directory攻撃の検知

Anti-Forensics手法とその対策

スケールアップとAI活用

CTF&最終発表