Digital forensics and security incident response
After an incident, the quality of the investigation determines how well the facts are understood. Structure the collection and analysis of digital traces while preserving their integrity. Develop a rigorous approach to support your conclusions and contribute to incident response.
- Duration
- 3 days 21 hours
- Code
- CYBER001FR Code
Presentation
Master two essential capabilities for tackling cyberattacks: incident response to contain the threat and forensic analysis to conduct a rigorous digital investigation. This course teaches you to collect and preserve digital evidence methodically to understand every stage of an attack and strengthen your security for the long term.
Our 3-day programme offers practical immersion in modern investigation techniques. You will master the full incident response lifecycle, from preparation to remediation. Beyond processes, you will apply advanced collection methodologies on Windows and Linux systems, exploring complex artefacts such as those found in RAM or web browsers. Throughout the course, you will work with recognised investigation tools, preparing you for real-world situations.
This course equips you with immediately applicable skills, assessed through a final attack simulation. You will be able to conduct a complete technical investigation and synthesise it in a clear, compelling forensic analysis report. This combination of technical and writing expertise is a major asset for advancing your cybersecurity career and specialising in crisis management.
Objectives
By the end of this digital forensics and incident response course, you will be able to:
- structure and lead an incident response plan, mastering every lifecycle stage, from preparation and detection through threat eradication and business recovery;
- apply digital evidence collection best practices (disk imaging, RAM capture), ensuring evidence integrity for subsequent analysis;
- conduct forensic analysis on Windows and Linux systems, examining event logs, web browsers and other artefacts to identify traces of compromise;
- write a clear, structured technical analysis report, presenting investigation findings in a factual, actionable manner.
Program
Day 1: master incident response fundamentals
- Incident response strategy: preparing teams, tools and procedures.
- Incident identification and classification: detection, initial analysis and threat prioritisation techniques.
- Threat containment: methods for isolating compromised systems to limit impact.
- Crisis communication: internal and external notification procedures.
- Eradication and recovery: processes for eliminating the root cause of an attack and safely restoring services.
Day 2: apply forensic analysis fundamentals
- Evidence acquisition and chain of custody: disk imaging techniques and volatile data collection.
- Data recovery (file carving): principles and implementation for reconstructing deleted files.
- System log analysis: using Windows, Linux and application logs to retrace suspicious activity.
- Network communication analysis: identifying traces of an attack in traffic captures (PCAP).
Day 3: deepen forensic analysis with advanced concepts
- Large-scale investigation techniques: using indexing tools to accelerate searches.
- Web browser analysis: investigating user activity artefacts (history, cache, sessions).
- RAM analysis: searching for transient evidence not present on disk (processes, malware, etc.).
- Malicious email analysis: techniques for examining headers and attachments (phishing, malware).
- Forensic analysis reports: structure, writing best practices and clear presentation of findings.
Audience
This course is intended for:
- cybersecurity analysts and engineers (SOC teams, CSIRTs, etc.) seeking to master post-incident investigation methodologies for in-depth analysis of alerts and compromises;
- incident response professionals who want to structure their approach, master new tools and follow industry best practices;
- experienced system and network administrators who are often on the front line when an alert arises and want to develop effective practices for preserving evidence, performing initial analyses and contributing to the investigation.
Prerequisites
This course requires the following prerequisites:
- Solid knowledge of system and networking fundamentals: understanding of operating system architecture (processes, memory management and file systems) and key protocols (TCP/IP, DNS and HTTP).
- General cybersecurity awareness: familiarity with the main types of threats and vulnerabilities (malware, phishing, common web vulnerabilities, etc.).
- Practical system administration experience: confidence using the command line on Windows and Linux, and knowledge of service and permission management.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Quiz / multiple-choice questions
- Practical exercises
Course highlights
- Direct field expertise: learn directly from an incident response and digital forensics consultant who shares practical experience from real cyberattack investigations.
- Practical, hands-on immersion: theory is immediately put into practice. Each concept is explored through workshops, realistic case studies and use of professional and open-source tools.
- A full-scale attack simulation: to assess your skills, you will be immersed in a complete attack simulation. You will lead the investigation from start to finish in a secure lab environment, as in a real investigation.
- Immediately applicable skills: leave with more than knowledge: gain methodologies, procedures and practices you can apply the next day to analyse and respond effectively to security incidents.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
fr
en