Verified credential
Cyber Defense Responder (CDR)
Awarded to Warawut Manosong on August 1, 2026
Description
The Cyber Defense Responder (CDR) validates Tier 1 alert triage and incident response judgment.
Holders passed a timed, scenario-based exam where they read real investigation artifacts, including email headers, Windows event logs, process trees, registry entries, PowerShell, and threat intelligence reports, then classified activity as malicious or benign and prioritized escalation.
The exam is vendor agnostic, tests methodology and judgment under time pressure, and requires a score of 80% to pass. The CDR is the third badge in the SOC Analyst Path, following the CDT and CDA, and the gateway to the instructor-certified CDCA and CDCP.
Criteria
- Pass the CDR Exam with a score of 80% or higher (23 of 28)
- 28 scenario-based questions covering email security, log and event analysis, Windows triage, and cyber threat intelligence
- Completed within a 60-minute time limit
Domains Covered:
- Email Security (header analysis, authentication, phishing identification)
- Log & Event Analysis (Windows events, SIEM queries, YARA basics)
- Windows Triage (persistence mechanisms, process analysis, network artifacts, PowerShell analysis)
- Cyber Threat Intelligence (indicator analysis, threat actor reports, tactical decision-making)