Skip to main content

Home Specialist skills Security FOR608: Enterprise-Class Incident Response and Threat Hunting

FOR608: Enterprise-Class Incident Response and Threat Hunting

  • bullet point
    Understand when incident response requires in-depth host interrogation or light-weight mass collection along with discussing best practices for responding to Azure, M365 and AWS cloud platforms
  • bullet point
    Collect host- and cloud-based forensic data from large environments
  • bullet point
    Correlate and analyse data across multiple data types and machines using a myriad of analysis techniques
  • bullet point
    Develop IOC signatures and analytics to expand searching capabilities and enable rapid detection of similar incidents in the future
  • bullet point
    Track incidents and indicators from beginning to end using built-for-purpose incident response engagement tooling

Overview

Off the shelf (OTS)

FOR608: Enterprise-Class Incident Response and Threat Hunting focuses on identifying and responding to incidents too large to focus on individual machines. By using example tools built to operate at enterprise-class scale, students learn the techniques to collect focused data for incident response and threat hunting, and dig into analysis methodologies to learn multiple approaches to understand attacker movement and activity across hosts of varying functions and operating systems by using an array of analysis techniques.

Delivery method
Face to face icon

Face to face

Virtual icon

Virtual

Digital icon

Digital

Course duration
Duration icon

48 hours

Competency level
Expert icon

Expert

Pink building representing strand 4 of the campus map
Delivery method
  • face to face icon

    Face to face

  • Virtual icon

    Virtual

  • Digital icon

    Digital

Course duration
Duration icon

48 hours

Competency level
  • Expert icon

    Expert