Perform a search on the site.

Your currency

Digital forensics and security incident response

After an incident, the quality of the investigation determines how well the facts are understood. Structure the collection and analysis of digital traces while preserving their integrity. Develop a rigorous approach to support your conclusions and contribute to incident response.

Duration
3 days 21 hours
Code
CYBER001FR Code

Presentation

Master two essential capabilities for tackling cyberattacks: incident response to contain the threat and forensic analysis to conduct a rigorous digital investigation. This course teaches you to collect and preserve digital evidence methodically to understand every stage of an attack and strengthen your security for the long term.

Our 3-day programme offers practical immersion in modern investigation techniques. You will master the full incident response lifecycle, from preparation to remediation. Beyond processes, you will apply advanced collection methodologies on Windows and Linux systems, exploring complex artefacts such as those found in RAM or web browsers. Throughout the course, you will work with recognised investigation tools, preparing you for real-world situations.

This course equips you with immediately applicable skills, assessed through a final attack simulation. You will be able to conduct a complete technical investigation and synthesise it in a clear, compelling forensic analysis report. This combination of technical and writing expertise is a major asset for advancing your cybersecurity career and specialising in crisis management.

Objectives

By the end of this digital forensics and incident response course, you will be able to:

  • structure and lead an incident response plan, mastering every lifecycle stage, from preparation and detection through threat eradication and business recovery;
  • apply digital evidence collection best practices (disk imaging, RAM capture), ensuring evidence integrity for subsequent analysis;
  • conduct forensic analysis on Windows and Linux systems, examining event logs, web browsers and other artefacts to identify traces of compromise;
  • write a clear, structured technical analysis report, presenting investigation findings in a factual, actionable manner.
Last update: 24/09/2026