Skip to content
Advanced Intermediate Certificate

Digital Forensics & Incident Response

Work a compromise from first alert to final report — evidence handling, timeline reconstruction, and disclosure.

0.4 hr 1 lectures 5 lab ranges 6 weeks

Description

Structured around full incident scenarios rather than isolated exercises. You get a compromised environment and work it through properly, including the parts people skip: evidence preservation and the written report.

The reporting is assessed as heavily as the technical analysis, because in a real incident it is the deliverable.

Who is this course for?

  • SOC analysts
  • Security testers
  • Network engineers
  • Incident responders

What you will learn

Incident response process and its correct order Evidence preservation and chain of custody Disk and memory forensics Log analysis and timeline reconstruction Malware behaviour analysis in isolation Determining whether data was exfiltrated Writing reports for legal and insurance audiences

Course curriculum

The curriculum for this course is being published. It will appear here shortly.

Lab ranges included

Compromised Host Triage Medium
Segmented Network Range Medium
Web Application Assessment Range Medium
API Security Range Medium
Incident Response Range Medium