Incident Response and Network Forensics Training at InfoSec Institute
Without a doubt, the sophistication and threats caused by malicious attacks have continued to increase at a rapid level. If you plan on responding to a security incident, you must be abel to meet the challenges that these sophistcated attackers present.
InfoSec Institute helps you meet the challenges presented by attackers in this hands-on Incident Response class. You will learn effective detection, response, and remediation strategies that will enable you and your organization to properly contain a security incident.
This five day class has been specifically designed for technical information technology professionals, targeted at technical responders, who respond to computer security incidents. In this course, you will go over many real-world case studies, and gain the skills you need to respond to incidents via hands-on lab exercises.
A sample of the topics covered in this class are:
- Understanding the methodology of an effective Incident Response process
- Incident Response Phases
- Create working documentation and checklists usable during a real-world response crisis
- Understand the proper incident response process for live compromised Windows and Unix systems
- Learn how to detect and confirm attacks against Windows and Unix
systems
- Create a system response toolkit to be used in the heat of a crisis
- Learn how to discover attack signatures in Windows and Unix log files
- Use Log Parser 2.2 to recover critical information from Windows systems
- Understand what volatile evidence is present on a system you must collect and preserver prior to system power down
- Get hands-on experience retrieving and writing to disk memory from suspicious processes
- Detect and remove Win32 Rootkits, LKM Rootkits and Trojaned files
- Discover hidden files files and processes
- Analyze and export data from critical system files in Windows including hiberfil.sys and pagefile.sys
- Learn how to recover deleted or overwritten files from Kernel memory on Unix systems
- Perform basic Reverse Engineering of unknown process and binaries, without having to know assembly language.
For more details contact an account represtentative at +1-708-660-0721
|