AdvancedContent in Spanish
Incident response and digital forensics
Become the person who knows what to do when the alarm goes off. This advanced course covers the full incident response cycle according to the NIST framework, from preparation to lessons learned, and trains you in logging and SIEM, triage, threat intelligence and indicators of compromise, memory, disk and network forensics, chain of custody and crisis communication. It is the fifth and last course of the Professional Certificate in Cybersecurity, the step before the capstone exam.
9 lessons 12 hours 900 XP
Start the courseSyllabus
Module 1 · DFIR fundamentals and the NIST lifecycle
- 1The incident response lifecycle according to NIST50 min
- 2Preparation: the plan, the team and the tools50 min
Module 2 · Detection and analysis: logging, SIEM and triage
- 3Logging and monitoring: the raw material of analysis55 min
- 4SIEM: correlation, detection rules and alerts60 min
- 5Triage: prioritizing and deciding the scope of the incident55 min
Module 3 · Forensic analysis: evidence, memory, disk and network
- 6Chain of custody and evidence integrity50 min
- 7Memory, disk and network forensics60 min
- 8Indicators of compromise and threat intelligence55 min
Module 4 · Coordination: containment, playbooks and crisis
- 9Playbooks, containment-eradication-recovery and crisis communication55 min