Advanced Incident Response, Threat Hunting, and Digital Forensics

Threat hunting and Incident response tactics and procedures have evolved rapidly over the past several years. Your team can no longer afford to use antiquated incident response and threat hunting techniques that fail to properly identify compromised systems. The key is to constantly look for attacks that get past security systems, and to catch intrusions in progress, rather than after attackers have completed their objectives and done worse damage to the organization. For the incident responder, this process is known as "threat hunting".FOR508 teaches advanced skills to hunt, identify, counter, and recover from a wide range of threats within enterprise networks, including APT nation-state adversaries, organized crime syndicates, and hactivists.

Course syllabus:

  1. Advanced Incident Response and Threat Hunting

  2. Intrusion Analysis

  3. Memory Forensics in Incident Response and Threat Hunting

  4. Timeline Analysis

  5. Incident Response and Hunting Across the Enterprise, Advanced Adversary and Anti Forensic Detection

  6. The APT Threat Group Incident Response Challenge