DIG-FORNSC-IR.AJ1
Digital Forensics and Incident Response
Learn how to build a strong defense fabric using the latest digital forensics and incident response techniques.
- Practice in 29 Hands-On Labs — nothing to install
- 20 Interactive Lessons and 123 topics mapped to the official exam objectives
- 180 Practice Test Questions
Beginner Self-paced · 1 year access
29 Hands-On LiveLabs
Practice real IT tasks in guided environments.
- Real environments
- Auto-graded
- No installation
01 / Skills you'll get
What you will be able to do
- Engage and manage IR teams, utilizing Security Orchestration, Automation, and Response (SOAR).
- Apply various incident investigation analyses to understand the cyber kill chain and the diamond model of intrusion analysis.
- Collect and analyze network evidence from firewalls, proxy logs, NetFlow, and packet captures using tools like Wireshark.
- Take actions to respond to ransomware incidents and investigate cyberattacks.
- Set up and use malware sandboxes for static and dynamic analysis using tools like ClamAV and YARA.
- Source and leverage threat intelligence using the MITRE ATT&CK framework.
- Work with Indicators of Compromise (IOCs) and Indicators of Attack (IOAs).
- Create hypotheses, plan and execute threat hunts, and apply digital forensic techniques and EDR tools for threat hunting.
- Manage and analyze log files using SIEMs and other tools, with a focus on Windows Event Logs.
Course Highlights
-
20 Structured Lessons Comprehensive coverage of core course objectives
-
29 Hands-On LiveLabs Interactive guided scenarios with instant evaluation
-
180 Practice Questions Assessment tests with detailed answer rationales
-
1 Year Full Access Self-paced learning accessible anytime on all devices
02 / Lessons & labs
See exactly what you will learn and practice
Lessons
20 Interactive Lessons · 123 topics01 Preface 3 topics +
- Who this course is for
- What this course covers
- To get the most out of this course
02 Understanding Incident Response 7 topics +
- The IR process
- The IR framework
- The IR plan
- The IR playbook/handbook
- Testing the IR framework
- Summary
- Further reading
03 Managing Cyber Incidents 7 topics +
- Engaging the incident response team
- SOAR
- Incorporating crisis communications
- Incorporating containment strategies
- Getting back to normal – eradication, recovery, and post-incident activity
- Summary
- Further reading
04 Fundamentals of Digital Forensics 6 topics · 1 LiveLab +
- An overview of forensic science
- Locard’s exchange principle
- Legal issues in digital forensics
- Forensic procedures in incident response
- Summary
- Further reading
1 LiveLab in this lesson — see the labs panel →
05 Investigation Methodology 6 topics · 1 LiveLab +
- An intrusion analysis case study: The Cuckoo’s Egg
- Types of incident investigation analysis
- Functional digital forensic investigation methodology
- The cyber kill chain
- The diamond model of intrusion analysis
- Summary
1 LiveLab in this lesson — see the labs panel →
06 Collecting Network Evidence 8 topics · 5 LiveLab +
- An overview of network evidence
- Firewalls and proxy logs
- NetFlow
- Packet capture
- Wireshark
- Evidence collection
- Summary
- Further reading
5 LiveLab in this lesson — see the labs panel →
07 Acquiring Host-Based Evidence 7 topics · 3 LiveLab +
- Preparation
- Order of volatility
- Evidence acquisition
- Acquiring volatile memory
- Acquiring non-volatile evidence
- Summary
- Further reading
3 LiveLab in this lesson — see the labs panel →
08 Remote Evidence Collection 5 topics · 1 LiveLab +
- Enterprise incident response challenges
- Endpoint detection and response
- Velociraptor overview and deployment
- Velociraptor scenarios
- Summary
1 LiveLab in this lesson — see the labs panel →
09 Forensic Imaging 7 topics · 2 LiveLab +
- Understanding forensic imaging
- Tools for imaging
- Preparing a staging drive
- Using write blockers
- Imaging techniques
- Summary
- Further reading
2 LiveLab in this lesson — see the labs panel →
10 Analyzing Network Evidence 6 topics · 2 LiveLab +
- Network evidence overview
- Analyzing firewall and proxy logs
- Analyzing NetFlow
- Analyzing packet captures
- Summary
- Further reading
2 LiveLab in this lesson — see the labs panel →
11 Analyzing System Memory 6 topics · 2 LiveLab +
- Memory analysis overview
- Memory analysis methodology
- Memory analysis tools
- Memory analysis with Strings
- Summary
- Further reading
2 LiveLab in this lesson — see the labs panel →
12 Analyzing System Storage 7 topics · 2 LiveLab +
- Forensic platforms
- Autopsy
- Master File Table analysis
- Prefetch analysis
- Registry analysis
- Summary
- Further reading
2 LiveLab in this lesson — see the labs panel →
13 Analyzing Log Files 6 topics · 2 LiveLab +
- Logs and log management
- Working with SIEMs
- Windows Logs
- Analyzing Windows Event Logs
- Summary
- Further reading
2 LiveLab in this lesson — see the labs panel →
14 Writing the Incident Report 7 topics +
- Documentation overview
- Executive summary
- Incident investigation report
- Forensic report
- Preparing the incident and forensic report
- Summary
- Further reading
15 Ransomware Preparation and Response 6 topics · 1 LiveLab +
- History of ransomware
- Conti ransomware case study
- Proper ransomware preparation
- Eradication and recovery
- Summary
- Further reading
1 LiveLab in this lesson — see the labs panel →
16 Ransomware Investigations 7 topics · 2 LiveLab +
- Ransomware initial access and execution
- Discovering credential access and theft
- Investigating post-exploitation frameworks
- Command and Control
- Investigating lateral movement techniques
- Summary
- Further reading
2 LiveLab in this lesson — see the labs panel →
17 Malware Analysis for Incident Response 8 topics · 3 LiveLab +
- Malware analysis overview
- Setting up a malware sandbox
- Static analysis
- Dynamic analysis
- ClamAV
- YARA
- Summary
- Further reading
3 LiveLab in this lesson — see the labs panel →
18 Leveraging Threat Intelligence 7 topics · 2 LiveLab +
- Threat intelligence overview
- Sourcing threat intelligence
- The MITRE ATT&CK framework
- Working with IOCs and IOAs
- Threat intelligence and incident response
- Summary
- Further reading
2 LiveLab in this lesson — see the labs panel →
19 Threat Hunting 7 topics +
- Threat hunting overview
- Crafting a hypothesis
- Planning a hunt
- Digital forensic techniques for threat hunting
- EDR for threat hunting
- Summary
- Further reading
20 Appendix +
Hands-On Labs Our edge
29 LiveLabs- Completing the Chain of Custody
- Performing Reconnaissance on a Network
- Installing a DHCP Server
- Performing a Proxy Server Operation
- Creating a Firewall Rule
- Capturing Packet Using RawCap
- Using tcpdump to Capture Packets
- Using WinPmem for Memory Acquisition
- Using FTK Imager
- Using FTK Imager for Obtaining Protected Files
- Using the Velociraptor Server
- Preparing a Staging Drive
- Using EnCase Imager
- Working with NetworkMiner
- Capturing a Packet Using Wireshark
- Analyzing Malicious Activity in Memory Using Volatility
- Working with Strings in Linux
- Analyzing Forensic Case with Autopsy
- Viewing the Windows File Registry
- Creating an Event Log View
- Examining Windows Event Logs Using DeepBlueCLI
- Understanding LPE
- Using Social Engineering Techniques to Plan an Attack
- Passing the Hash Using Mimikatz
- Analyzing Malware Using Virustotal
- Using Process Explorer
- Handling Potential Malware Using ClamAV
- Examining MITRE ATT&CK
- Footprinting a Website
03 / FAQs
Questions before you start
What is digital forensics and incident response? +
Are there any prerequisites for this course? +
What tools and software will I learn to use in this cybersecurity forensic course? +
You will learn to use the following tools:
Incident Response Tools:
- SOAR (Security Orchestration, Automation, and Response)
- Network Evidence Collection and Analysis:
- Firewalls
- Proxy logs
- NetFlow
- Packet capture
- Wireshark
- RawCap
- tcpdump
- NetworkMiner
Host-Based Evidence Collection and Analysis:
- WinPmem for memory acquisition
- FTK Imager
- Velociraptor
- EnCase Imager
- Volatility (for memory analysis)
- Strings (Linux tool)
Digital Forensics Platforms and Tools:
- Forensic platforms
- Autopsy
- Master File Table analysis tools
- Prefetch analysis tools
- Registry analysis tools
Log Analysis:
- SIEMs (Security Information and Event Management systems)
- Windows Event Logs
- DeepBlueCLI
Malware Analysis:
- Malware sandbox
- ClamAV
- YARA
- VirusTotal
- Process Explorer
Threat Intelligence and Threat Hunting:
- MITRE ATT&CK framework
- Maltego
How much does a digital forensics and incident response specialist make in a month?+
Get Hands-on! Get DFIR Skills!
Discover how to use advanced DFIR tools and frameworks to build a strong network security infrastructure.
- 1 year of full access
- 29 LiveLab included
- Certificate of completion
No credit card required