Incident Response & DFIR Analyst Path
Analysts who want to run toward the incident: detect, investigate, and recover from real attacks, and stand up the forensic evidence behind them.
- Run an incident end to end against the NIST SP 800-61 lifecycle, from declaration to lessons learned
- Acquire and analyze disk, memory, and network evidence with a defensible chain of custody
- Contain and recover from ransomware, business email compromise, and insider incidents, then write the report
$1,000 or 3× $333
Save $97 vs. courses separately
The journey
- 1
Incident Response Foundations
The NIST SP 800-61 lifecycle end to end
- 2
Digital Forensics Essentials
Acquire and analyze digital evidence
- 3
Incident Response in Practice
Work real incidents from alert to report
Capstone: run a live incident end to end
Forensic timeline, a containment and eradication plan, and a full incident report