Cybersecurity Foundations: Incident Response
1h 39mBeginner2025-11-14
Authors

Mike Wylie
Information Security Expert and Threat Manager
Course details
Are you ready to get up and running and learn more about the ins and outs of cybersecurity? This course provides you with a foundational overview of incident response, equipping you with the skills you need to prepare for, respond to, and recover from potentially devastating cybersecurity incidents. Join instructor Mike Wylie as he covers key concepts, policies, procedures, and best practices essential for effective incident management. An ideal fit for both technical and non-technical professionals who play a role in an organization's incident response efforts, by the end of this course, you’ll be prepared to maintain and improve your organizational security posture.
Learning objectives
Identify the fundamental components of incident response frameworks (NIST and SANS), key terminology, and the distinction between security events and incidents to establish a solid foundation for effective cybersecurity response activities.
Apply structured incident handling methodologies including recording, triage, notification protocols, and digital forensic collection techniques to manage cybersecurity incidents systematically across diverse organizational environments.
Analyze platform-specific artifacts and log sources from Windows, Linux, macOS, and network environments to detect indicators of compromise, reconstruct attack timelines, and gather forensic evidence during incident investigations.
Evaluate incident response policies, team structures, and communication strategies to assess their effectiveness in meeting organizational needs, legal requirements, and compliance standards while addressing unique challenges in cloud environments.
Develop comprehensive incident response capabilities by integrating endpoint detection and response (EDR) tools, memory forensics techniques, and cross-platform triage methodologies to create robust investigation workflows that enhance organizational security posture.
Learning objectives
Identify the fundamental components of incident response frameworks (NIST and SANS), key terminology, and the distinction between security events and incidents to establish a solid foundation for effective cybersecurity response activities.
Apply structured incident handling methodologies including recording, triage, notification protocols, and digital forensic collection techniques to manage cybersecurity incidents systematically across diverse organizational environments.
Analyze platform-specific artifacts and log sources from Windows, Linux, macOS, and network environments to detect indicators of compromise, reconstruct attack timelines, and gather forensic evidence during incident investigations.
Evaluate incident response policies, team structures, and communication strategies to assess their effectiveness in meeting organizational needs, legal requirements, and compliance standards while addressing unique challenges in cloud environments.
Develop comprehensive incident response capabilities by integrating endpoint detection and response (EDR) tools, memory forensics techniques, and cross-platform triage methodologies to create robust investigation workflows that enhance organizational security posture.
Concepts
Introduction
- First look at incident response
Introduction to Incident Response
- Defining incident response (IR)
- Considering legal and compliance incidents
- Building a top-notch incident response team
- Comparing SANS and NIST frameworks
- Developing an incident response policy
Incident Handling
- Incident recording, triaging, and notification best practices
- Communicating effectively during an incident
- Using digital forensic collection methods for incident response
- Managing incident response challenges in cloud environments
- Leveraging EDR for incident handling
Network Incident Response
- Collecting data sources for threat detection and response
- Filtering network data for efficient incident response
- Recognizing signs and indicators in network incident response
Windows Incident Response
- Windows - Investigating logs
- Windows - Analyzing artifacts for execution activity
- Windows - Analyzing artifacts for user activity
- Windows - Introducing memory forensics
- Windows - Triaging tools and techniques
Linux Incident Response
- Linux - Collecting event logs
- Linux - Analyzing artifacts for execution evidence SPLIT
- Linux - Analyzing artifacts for user activity SPLIT
- Linux - Investigating Linux command history
- Linux - Detecting incidents and SSH artifacts
- Linux - Triaging tools and techniques
MacOS Incident Response
- macOS - Investigating logs
- macOS - Analyzing artifacts for execution
- macOS - Analyzing artifacts for user activity
Conclusion
- Next steps