DIG-FORNSC-IR.AJ1
Digital Forensics and Incident Response
Learn how to build a strong defense fabric using the latest digital forensics and incident response techniques.
- Practice in 29 Laboratorios prácticos — nothing to install
- 20 Lecciones interactivas y 123 topics mapped to the official exam objectives
- 180 Preguntas del examen de práctica
Beginner A tu propio ritmo · 1 año de acceso
29 LiveLabs prácticos
Practice real IT tasks in guided environments.
- Entornos reales
- Calificación automática
- Sin instalación
01 / Habilidades que obtendrás
What you will be able to do
- Engage and manage IR teams, utilizing Security Orchestration, Automation, and Response (SOAR).
- Apply various incident investigation analyses to understand the cyber kill chain and the diamond model of intrusion analysis.
- Collect and analyze network evidence from firewalls, proxy logs, NetFlow, and packet captures using tools like Wireshark.
- Take actions to respond to ransomware incidents and investigate cyberattacks.
- Set up and use malware sandboxes for static and dynamic analysis using tools like ClamAV and YARA.
- Source and leverage threat intelligence using the MITRE ATT&CK framework.
- Work with Indicators of Compromise (IOCs) and Indicators of Attack (IOAs).
- Create hypotheses, plan and execute threat hunts, and apply digital forensic techniques and EDR tools for threat hunting.
- Manage and analyze log files using SIEMs and other tools, with a focus on Windows Event Logs.
Course Highlights
-
20 Lecciones estructuradas Cobertura completa de los objetivos principales del curso
-
29 LiveLabs prácticos Escenarios interactivos guiados con evaluación instantánea
-
180 Preguntas de práctica Pruebas de evaluación con justificaciones de respuesta detalladas
-
1 año de acceso completo Aprendizaje a tu propio ritmo, accesible en cualquier momento y en todos los dispositivos
02 / Lecciones y laboratorios
See exactly what you will learn and practice
Plan de estudios
20 Lecciones interactivas · 123 topics01 Preface 3 topics +
- Who this course is for
- What this course covers
- To get the most out of this course
02 Understanding Incident Response 7 topics +
- The IR process
- The IR framework
- The IR plan
- The IR playbook/handbook
- Testing the IR framework
- Summary
- Further reading
03 Managing Cyber Incidents 7 topics +
- Engaging the incident response team
- SOAR
- Incorporating crisis communications
- Incorporating containment strategies
- Getting back to normal – eradication, recovery, and post-incident activity
- Summary
- Further reading
04 Fundamentals of Digital Forensics 6 topics · 1 Laboratorio en vivo +
- An overview of forensic science
- Locard’s exchange principle
- Legal issues in digital forensics
- Forensic procedures in incident response
- Summary
- Further reading
1 Laboratorio en vivo in this lesson — see the labs panel →
05 Investigation Methodology 6 topics · 1 Laboratorio en vivo +
- An intrusion analysis case study: The Cuckoo’s Egg
- Types of incident investigation analysis
- Functional digital forensic investigation methodology
- The cyber kill chain
- The diamond model of intrusion analysis
- Summary
1 Laboratorio en vivo in this lesson — see the labs panel →
06 Collecting Network Evidence 8 topics · 5 Laboratorio en vivo +
- An overview of network evidence
- Firewalls and proxy logs
- NetFlow
- Packet capture
- Wireshark
- Evidence collection
- Summary
- Further reading
5 Laboratorio en vivo in this lesson — see the labs panel →
07 Acquiring Host-Based Evidence 7 topics · 3 Laboratorio en vivo +
- Preparation
- Order of volatility
- Evidence acquisition
- Acquiring volatile memory
- Acquiring non-volatile evidence
- Summary
- Further reading
3 Laboratorio en vivo in this lesson — see the labs panel →
08 Remote Evidence Collection 5 topics · 1 Laboratorio en vivo +
- Enterprise incident response challenges
- Endpoint detection and response
- Velociraptor overview and deployment
- Velociraptor scenarios
- Summary
1 Laboratorio en vivo in this lesson — see the labs panel →
09 Forensic Imaging 7 topics · 2 Laboratorio en vivo +
- Understanding forensic imaging
- Tools for imaging
- Preparing a staging drive
- Using write blockers
- Imaging techniques
- Summary
- Further reading
2 Laboratorio en vivo in this lesson — see the labs panel →
10 Analyzing Network Evidence 6 topics · 2 Laboratorio en vivo +
- Network evidence overview
- Analyzing firewall and proxy logs
- Analyzing NetFlow
- Analyzing packet captures
- Summary
- Further reading
2 Laboratorio en vivo in this lesson — see the labs panel →
11 Analyzing System Memory 6 topics · 2 Laboratorio en vivo +
- Memory analysis overview
- Memory analysis methodology
- Memory analysis tools
- Memory analysis with Strings
- Summary
- Further reading
2 Laboratorio en vivo in this lesson — see the labs panel →
12 Analyzing System Storage 7 topics · 2 Laboratorio en vivo +
- Forensic platforms
- Autopsy
- Master File Table analysis
- Prefetch analysis
- Registry analysis
- Summary
- Further reading
2 Laboratorio en vivo in this lesson — see the labs panel →
13 Analyzing Log Files 6 topics · 2 Laboratorio en vivo +
- Logs and log management
- Working with SIEMs
- Windows Logs
- Analyzing Windows Event Logs
- Summary
- Further reading
2 Laboratorio en vivo in this lesson — see the labs panel →
14 Writing the Incident Report 7 topics +
- Documentation overview
- Executive summary
- Incident investigation report
- Forensic report
- Preparing the incident and forensic report
- Summary
- Further reading
15 Ransomware Preparation and Response 6 topics · 1 Laboratorio en vivo +
- History of ransomware
- Conti ransomware case study
- Proper ransomware preparation
- Eradication and recovery
- Summary
- Further reading
1 Laboratorio en vivo in this lesson — see the labs panel →
16 Ransomware Investigations 7 topics · 2 Laboratorio en vivo +
- Ransomware initial access and execution
- Discovering credential access and theft
- Investigating post-exploitation frameworks
- Command and Control
- Investigating lateral movement techniques
- Summary
- Further reading
2 Laboratorio en vivo in this lesson — see the labs panel →
17 Malware Analysis for Incident Response 8 topics · 3 Laboratorio en vivo +
- Malware analysis overview
- Setting up a malware sandbox
- Static analysis
- Dynamic analysis
- ClamAV
- YARA
- Summary
- Further reading
3 Laboratorio en vivo in this lesson — see the labs panel →
18 Leveraging Threat Intelligence 7 topics · 2 Laboratorio en vivo +
- Threat intelligence overview
- Sourcing threat intelligence
- The MITRE ATT&CK framework
- Working with IOCs and IOAs
- Threat intelligence and incident response
- Summary
- Further reading
2 Laboratorio en vivo in this lesson — see the labs panel →
19 Threat Hunting 7 topics +
- Threat hunting overview
- Crafting a hypothesis
- Planning a hunt
- Digital forensic techniques for threat hunting
- EDR for threat hunting
- Summary
- Further reading
20 Appendix +
Laboratorios prácticos Our edge
29 Laboratorio en vivos- Completing the Chain of Custody
- Performing Reconnaissance on a Network
- Installing a DHCP Server
- Performing a Proxy Server Operation
- Creating a Firewall Rule
- Capturing Packet Using RawCap
- Using tcpdump to Capture Packets
- Using WinPmem for Memory Acquisition
- Using FTK Imager
- Using FTK Imager for Obtaining Protected Files
- Using the Velociraptor Server
- Preparing a Staging Drive
- Using EnCase Imager
- Working with NetworkMiner
- Capturing a Packet Using Wireshark
- Analyzing Malicious Activity in Memory Using Volatility
- Working with Strings in Linux
- Analyzing Forensic Case with Autopsy
- Viewing the Windows File Registry
- Creating an Event Log View
- Examining Windows Event Logs Using DeepBlueCLI
- Understanding LPE
- Using Social Engineering Techniques to Plan an Attack
- Passing the Hash Using Mimikatz
- Analyzing Malware Using Virustotal
- Using Process Explorer
- Handling Potential Malware Using ClamAV
- Examining MITRE ATT&CK
- Footprinting a Website
03 / Preguntas frecuentes
Preguntas antes de empezar
What is digital forensics and incident response? +
Are there any prerequisites for this course? +
What tools and software will I learn to use in this cybersecurity forensic course? +
You will learn to use the following tools:
Incident Response Tools:
- SOAR (Security Orchestration, Automation, and Response)
- Network Evidence Collection and Analysis:
- Firewalls
- Proxy logs
- NetFlow
- Packet capture
- Wireshark
- RawCap
- tcpdump
- NetworkMiner
Host-Based Evidence Collection and Analysis:
- WinPmem for memory acquisition
- FTK Imager
- Velociraptor
- EnCase Imager
- Volatility (for memory analysis)
- Strings (Linux tool)
Digital Forensics Platforms and Tools:
- Forensic platforms
- Autopsy
- Master File Table analysis tools
- Prefetch analysis tools
- Registry analysis tools
Log Analysis:
- SIEMs (Security Information and Event Management systems)
- Windows Event Logs
- DeepBlueCLI
Malware Analysis:
- Malware sandbox
- ClamAV
- YARA
- VirusTotal
- Process Explorer
Threat Intelligence and Threat Hunting:
- MITRE ATT&CK framework
- Maltego
How much does a digital forensics and incident response specialist make in a month?+
Get Hands-on! Get DFIR Skills!
Discover how to use advanced DFIR tools and frameworks to build a strong network security infrastructure.
- 1 año de acceso completo
- 29 LiveLab incluido
- Certificado de finalización
No se requiere tarjeta de crédito