Skip to Content

Certified Incident Responder (eCIR)   


Request for price


Length: 5 day (40 hours)

 

Course objectives

After completing this course, students will be able to:

        • Detect & Correlate: Construct advanced queries in Splunk/ELK to identify Indicators of Compromise (IoCs) across disparate log sources.
        • Analyze Endpoints: Identify privilege escalation, credential dumping (LSASS/SAM), and persistence (Scheduled Tasks, Registry) in real-time.
        • Trace Network Chains: Use Wireshark and Zeek to reconstruct attack paths, lateral movement, and C2 (Command & Control) communications.
        • Perform Light Forensics: Deconstruct malicious documents (Macros/VBA) and perform static analysis on suspicious executables.
        • Apply Intelligence: Use MITRE ATT&CK to attribute behaviors to specific threat actor groups and TTPs.
        • Report & Remediate: Draft a professional investigation report that includes a timeline of events and actionable recovery recommendations.



Course outlines

    • Domain 1: Threat Detection & SIEM Operations
      • Constructing custom SIEM queries to identify malicious patterns.
      • Correlating multi-source log data to detect initial access.
      • Recognizing signs of attacker footholds in enterprise environments.
    • Domain 2: Endpoint & Network Analysis 
      • Analyzing telemetry for local user and system enumeration.
      • Differentiating privilege escalation and credential access (SAM/LSASS dumping).
      • Tracing lateral movement and authentication-based anomalies in PCAP data.
    • Domain 3: Digital Forensics & Evidence Analysis
      • Deconstructing malicious documents and extracting VBA payloads.
      • Static analysis of PE files for suspicious imports and metadata.
      • Examining Windows Registry for execution history and system changes.
    • Domain 4: Threat Intelligence & Attribution 
      • Mapping detected behaviors to MITRE ATT&CK TTPs.
      • Assessing behavioral patterns to attribute activity to specific APT groups.
    • Domain 5: Reporting & Communication 
      • Composing clear investigation reports including impact assessments.
      • Conveying technical findings (IOCs, tools, payloads) to stakeholders.

Download Outlines