Analyst will perform actual Incident Response activities on two different corporate
networks. Both Incident Response simulations are modeled after real-world
scenarios and cutting-edge attacking techniques.
Analyst will blend multiple detection and analysis methodologies to effectively
respond to the exam’s incidents.

After completing this course, Analyst will be able to understand:

  1. Network packet/traffic analysis
  2. Tools such as Wireshark, ELK & Splunk
  3. Actionable SIEM searches
  4. Event & log correlation
  5. Event analysis
  6. Process analysis and anomaly detection
  7. Understanding and detecting any stage of the “Cyber Kill Chain”
    (Information Gathering, Scanning, Exploitation, Post-exploitation)