Skip to main content
EduRails

Online learning made easy. For your whole institution.

AdvancedContent in Spanish

Incident response and digital forensics

Become the person who knows what to do when the alarm goes off. This advanced course covers the full incident response cycle according to the NIST framework, from preparation to lessons learned, and trains you in logging and SIEM, triage, threat intelligence and indicators of compromise, memory, disk and network forensics, chain of custody and crisis communication. It is the fifth and last course of the Professional Certificate in Cybersecurity, the step before the capstone exam.

9 lessons 12 hours 900 XP

Start the course

Syllabus

Module 1 · DFIR fundamentals and the NIST lifecycle

  1. 1The incident response lifecycle according to NIST50 min
  2. 2Preparation: the plan, the team and the tools50 min

Module 2 · Detection and analysis: logging, SIEM and triage

  1. 3Logging and monitoring: the raw material of analysis55 min
  2. 4SIEM: correlation, detection rules and alerts60 min
  3. 5Triage: prioritizing and deciding the scope of the incident55 min

Module 3 · Forensic analysis: evidence, memory, disk and network

  1. 6Chain of custody and evidence integrity50 min
  2. 7Memory, disk and network forensics60 min
  3. 8Indicators of compromise and threat intelligence55 min

Module 4 · Coordination: containment, playbooks and crisis

  1. 9Playbooks, containment-eradication-recovery and crisis communication55 min

Back to the catalogue