Host-based Incident Response

Learning objectives

Participants will learn the basics of Incident Response and forensic investigations by way of a fictional hacker attack. Thus the seminar starts off with a scenario that is explained step by step and which is accompanied by various exercises with different technologies and systems.

As part of training, measures will be developed and subsequently implemented. This includes the analysis of log files, the definition of Indicators of Compromise (IoC), as well as the classical forensic analysis of file systems.

Demarcation: The seminar teaches incident response and forensics fundamentals deployed in conjunction with workstations and servers. Locating and resolving network anomalies is covered in the “Incident Response Networks” course.


Highlights

  • Introduction to Incident Response
  • Live Response (Memory Dumps & Information Gathering)
  • Creating and using IoC
  • Securing Evidence (imaging)
  • Chain of Custody in Forensic Analysis
  • Fundamentals of File Systems
  • Post Mortem Analysis
  • Tracks in Slack Space
  • Tracks in Office Documents
  • Email Analysis and Exchange Forensics
  • Analysis of Windows Systems
  • Log Analysis and Finding Anomalies
  • Forensic Readiness

 

The exercises will be done on www.hacking-lab.com. Following the course, the labor environment is available to the participants for 30 days more.


Target group

  • Security Officers
  • IT Managers
  • System Engineers
  • Third-level Support
  • Incident Handlers
  • SOC Team Members


Prerequisite

  • Good technical understanding
  • Good knowledge of operating systems
  • Interest in security incidents
  • Interest in the forensic process
  • Interest in bits and bytes

CALENDAR

Basel Economic Forum 2019

The Basel Economic Forum is the economic forum for the trinational metropolitan region of Basel and northwestern Switzerland. The 6th event will take... Read more

New: Compass-Training "Internal Network and System Security" in Bern

In the 2-day seminar (in German) from February 11/12, 2020, you will get to know the most important basic concepts of IT security, attack tools and... Read more

KMU Swiss Forum 2020

The association «KMU Swiss» promotes the interaction between companies and specialists. He organises the annual KMU Swiss Forum. The next years motto... Read more

ALL DATES

NEWS

Vulnerability in totemodata

Fabio Poloni identified an XSS vulnerability in totemodata®. Read more

Gesundheitswesen: Ein leichtes Ziel für Hacker

«Heime & Spitäler» ist das Fachmedium für Entscheidungsträger von Schweizer Heimen und Spitäler. In der aktuellen Ausgabe beschreibt Compass Security... Read more

Vulnerablitity in VeloCloud™

Silas Bärtsch identified a vulnerability in VeloCloud™ (VMware), that allows a VeloCloud standard admin user to access user information of other... Read more

ARCHIVES

Compass Security Blog

Hacking Tools Cheat Sheet

Everyone knows: cheat sheets are cool! They are very useful if you already know the basics about a topic but you have to look up details when you are not sure about something. mehr

Introducing Web Vulnerabilities into Native Apps

Mobile applications nowadays make heavy use of WebViews in order to render their user interfaces. Frameworks such as PhoneGap / Apache Cordova are even used to implement most of the application's... mehr

ZUM BLOG