Back

Enterprise Incident Responder

This course is designed to equip participants with the knowledge and skills needed to effectively detect, respond to, and recover from cybersecurity incidents in an enterprise environment

Tarek

Lead Trainer

Description

Course Curriculum

Introduction to Enterprise Incident Response

4 lessons

The importance of incident response in an enterprise

Key components of incident response program

Preparation, Detection, Analysis and Remediation

Overview of incident response frameworks

Building and Incident Response Plan

5 lessons

Components of an Incident Response Plan

Defining roles and responsibilities

Establishing communication channels and protocols

Creating and testing playbooks

Testing and updating the incident response plan

Threat Intelligence and Incident Detection

3 lessons

Introduction to threat intelligence

How and when to use threat intelligence

Source of threat intelligence

Introduction to Windows Evidence

7 lessons

Network connections

Browser history

Windows prefetch

File system analysis

Windows registry

Event logs

Memory analysis

Invetigating Persistence

3 lessons

Understanding the attack lifecycle

Common persistence mechanisms

Investigating remote access techniques

Investigting Lateral Movement

4 lessons

Understanding Windows Credentials

Understanding Windows Credentials

Analyzing Logon Events

Investigating remote command execution

Investigting Web Attacks

2 lessons

Introduction to Web Logs

Investigating common web attacks

Post-Incident Activities and Lessons Learned

4 lessons

Conducting a post-incident review

Identifying gaps and areas for improvement

Updating incident response plans and playbooks

Continuous improvement and training