
Learn incident handling and response methodologies, from identification to recovery, across networks, cloud, email, and forensics. Build hands-on skills with tools, reporting, and exam-focused guidance for the ECIH.
Explore the five core information security elements: confidentiality, integrity, availability, authenticity, and non repudiation, and see how defense in depth, policies, and incident handling address threats and attacks.
Explore what constitutes a vulnerability, how to conduct vulnerability assessments, and the six phases of the vulnerability management lifecycle, from baseline and risk assessment to remediation and ongoing monitoring.
Threat assessments identify and model potential actions by bad actors, using internal and external threat data, threat intelligence, contextualization, and correlation to prioritize defense and incident handling.
Explore risk management vocabulary, defining threat, vulnerability, likelihood, and impact, and learn how risk equals threat times vulnerability, with countermeasures and residual risk.
Learn the nine-step risk assessment process within a three-phase risk management framework that identifies systems, threats, and vulnerabilities, then analyzes controls, likelihood, and impact to guide risk decisions.
Explore the NIST RMF and its six phases—categorize, select, implement, assess, authorize, monitor—for ongoing risk management.
Learn to master incident handling best practices, standards, and frameworks; implement auditing, due diligence, an incident response plan, and a CSIRT, guided by ISO 27001/27002, NIST, PCI DSS, and COBIT.
Assess the role of law in incident handling, including jurisdiction, law enforcement, GDPR, and US acts like SOX, HIPAA, FISMA, GLBA, DMCA, with 72-hour breach notification to supervisory authorities.
Prepare for incident handling and response by defining incident concepts and establishing the IH&R team. Learn about roles, planning, and evaluating the current security posture to restore operations quickly.
Master incident escalation and recording by assigning tasks through IH&R procedures. Support teams use ticketing systems to capture the who, what, when, where, why, and how, creating auditable trails.
Triaging incidents using analysis, validation, and IOC evidence to assess impact, then classify by categorization and severity for prioritized incident response and resource allocation.
Contain incidents by defining a boundary, triaging the incident, and marshaling resources to limit impact, while applying techniques like disabling systems and changing passwords for restoration.
Gather and analyze evidence and perform forensic analysis through an eight-step process, preserving a formal chain of custody while documenting findings, reporting to management, and considering external help when needed.
Learn the eradication phase of incident response: analyze vulnerabilities, remove threats, and patch the attack surface within the containment boundary, then audit before recovery.
Learn the recovery process flow after containment, focusing on restoring normal operations, validating backups, ensuring data integrity, and using a formal recovery plan grounded in a single source of truth.
Wrap up post incident activities by documenting findings, sharing lessons learned, and closing out the incident to finalize recovery. Update policies, logging practices, and disclosure to stakeholders for stronger response.
Define forensic techniques and the roles of first responders in tagging and bagging, preserving, and documenting evidence with chain of custody. Relate the phases to forensic readiness and policy.
Define digital evidence as information with probative value stored or transmitted digitally, including volatile and non-volatile data, and uphold relevance, weight, admissibility, authenticity, completeness, reliability, and believability with strict chain-of-custody.
Learn data acquisition in digital forensics, focusing on imaging, chain of custody, live and static data, and verifying integrity with hash values for admissible evidence.
Explore how to collect volatile data and evidence using the order of volatility, from registers to archival media, within a six-step incident response methodology.
Explore static evidence collection and anti-forensics through a six-step forensic workflow, from policy alignment and system preservation to imaging, data integrity, and clear, court-ready storytelling.
Identify malware types and components (ransomware, trojans, rats, viruses vs worms; crypters, downloaders, droppers, injectors, obfuscators, packers, payloads) and learn safe isolation with sandboxes and VMs.
Explore malware detection techniques across live system analysis, static analysis, and intrusion analysis to identify abnormal behavior and trace attack vectors.
Contain malware incidents by drawing a containment boundary around infected systems with approval to prevent spread and minimize impact. Gather logs, analyze propagation, disable unnecessary services, and remove malware.
Eradicate malware by removing all traces, identifying vulnerabilities and attack vectors, and applying multi-layer defenses—including antivirus, network security devices, and usage policies—to prevent reinfection and enable recovery.
Implement a holistic malware recovery by reimaging systems, restoring clean data, and scanning all endpoints and services; reinforce prevention, awareness, and threat mitigation to prevent reinfection.
Identify and contain email security incidents by understanding phishing variants such as spear phishing, whaling, and CEO scams, and by evaluating SPF, DKIM, and DMARC in email headers.
Learn how to prepare for network security incidents by building incident handling and response processes, centralized logging and SIEM, threat intelligence, and trained cross-functional teams.
Explore handling unauthorized access incidents by examining reconnaissance, sniffing and spoofing, firewall and IDS evasion, brute force attacks with MFA considerations, and containment steps.
Define inappropriate usage and protect corporate assets by enforcing acceptable use policies, detecting incidents via logs, and guiding containment, eradication, and recovery with HR and legal guidance.
Identify denial of service incidents, including DoS, DDoS, Dr DoS, and PDoS, and distinguish primary vs secondary victims. Use bogon lists, IP source guard, and load balancing for detection.
Learn to handle wireless network incidents by analyzing access control attacks, rogue access points, and ad hoc connections, and apply CIA triad—confidentiality, integrity, and availability—for secure wireless defense.
Explore three-tier web application architecture—presentation, web-service, and database layers—and learn common vulnerabilities, and follow a practical incident response road map with WAF and SIEM.
Detect and analyze web application security incidents by identifying indicators of compromise in logs, automating detection with regex and Snort, and examining SQL injection, XSS, and directory traversal.
Contain a web application security incident by isolating affected systems and applying ingress/egress filtering with proxies. Use WAFs, whitelisting, and server hardening to protect critical users via backup connectivity.
Eradicate web application security incidents by removing the attacker's footholds after containment, focusing on SQL injection, authentication and session management attacks, sensitive data exposure, and XML external entity attacks.
Learn to recover smartly from a web application security incident by restoring operations, patching vulnerabilities, rotating administrative passwords, validating backups, hardening the security perimeter, and using fuzz testing.
Explore the latest OWASP top 10 web application vulnerabilities, including injection, broken authentication, sensitive data exposure, cross-site scripting, and insecure deserialization, with practical defenses.
Outline the cloud computing characteristics per the NIST framework, including on-demand self-service, rapid elasticity, broad network access, and resource pooling, plus IaaS, PaaS, SaaS, deployment models, and cloud roles.
Explore incident handling in cloud environments across IaaS, PaaS, and SaaS, applying best practices for access control, data management, multi-cloud challenges, and eradication of security incidents.
Identify insider threats and their four categories, and implement defense in depth with least privilege, separation of duties, and security awareness training to detect, contain, and mitigate incidents.
Run buck-security on a Linux host to automate security checks and surface firewall, listening services, and world readable or setuid/setgid files for hardening.
Master volatile evidence collection on Linux and Windows by running real time commands, gathering hardware and session details, and analyzing logs with aureport and audit tools for incident response.
Explore how OSForensics assists incident handlers in discovering hidden forensic artifacts across memory, drives, and registries, creating cases, performing live acquisitions, and generating chain-of-custody reports.
Analyze non-volatile data with Autopsy to manage cases, inspect data sources from drive images, and drill into files, web history, email, and cloud storage for evidence.
In malware analysis, confirm suspicions with VirusTotal, then perform static and dynamic analysis in isolated sandboxes, using IDA Freeware for deeper code insight.
Trace email headers to identify origins, including sender IPs and geographic information. Use Email Tracker Pro and complementary tools to analyze attachments, traces, and URLs for incident response.
Learn OSSIM, a free SIEM, by setting up a virtual machine, configuring endpoints, and using the web interface to monitor logs, alerts, and threat intelligence.
Learn how to use Wireshark and Nmap to build an incident response toolkit, detect open ports, analyze traffic, and mitigate threats through hands-on scanning and traffic capture.
Learn how to set up Suricata as an intrusion detection system to monitor traffic, generate alerts, and manage rule files and logs, with integration options to siem.
Daniel demonstrates a sql injection on a dvwa-style web app, using or 1=1 and union select to reveal user data, while explaining logs and indicators of compromise for incident handlers.
Explore cross site scripting attacks in action, including reflected and stored XSS on DVWA, showing how malicious javascript can steal cookies and enable session hijacking.
The Certified Incident Handler v2 Exam Preparatory Course is designed to provide participants with the knowledge and skills required to handle and respond to various cybersecurity incidents. The course covers the fundamental principles of incident handling and response, including preparation, detection, containment, eradication, and recovery.
The course is intended for security officers, auditors, security professionals, site administrators, and anyone involved in incident handling and response. Participants will learn how to handle various types of incidents, including network security incidents, malicious code incidents, insider attacks, and physical security incidents.
Understanding the fundamentals of incident handling and response, including the incident handling process and procedures.
Developing an incident response plan and establishing communication channels to ensure a prompt and effective response to incidents.
Identifying and classifying incidents, analyzing their impact, and responding appropriately.
Implementing containment strategies to limit the impact of incidents and eradicating the cause of incidents.
The Certified Incident Handler v2 Exam Preparatory Course is designed for individuals who are looking to develop their skills and knowledge in incident handling and response. The course is particularly suitable for those who are responsible for maintaining the security of computer systems and networks, as well as those who are interested in pursuing a career in cybersecurity.
Overall, the Certified Incident Handler v2 Exam Preparatory Course aims to provide participants with the knowledge and skills needed to handle and respond to various cybersecurity incidents effectively. Upon completion of the course, participants will have the necessary knowledge to take the Certified Incident Handler certification exam and earn the Certified Incident Handler credential.
This course is NOT affiliated with EC-Council International Limited in any way, and content from this course is not approved by the organization.