Skip to main content
Certifications · GIAC (SANS Institute)

GIAC (SANS Institute)

GIAC GCIH

GIAC Certified Incident Handler

The incident response credential hiring managers trust: prove you can take a live incident from detection through containment and recovery, and that you know the attacker tools and techniques you are defending against.

ProfessionalSecurity OperationsBoot CampSelf-Paced5-day boot camp
Provider
GIAC (SANS Institute)
Exam
N/A
Level
Professional
Formats
Boot Camp · Self-Paced
Duration
5-day boot camp

What the exam covers

5

The full domain breakdown GIAC GCIH tests you on, and exactly what your prep with us is built around.

1

Incident response process & cyber investigations

2

Reconnaissance, scanning & enumeration

3

Password, web application & endpoint attacks

4

Post-exploitation, pivoting & evasion

5

Network, memory & malware investigations

Recommended before this

1

Credentials that build the foundation GIAC GCIH expects.

Where to go next

2

Natural next certifications once GIAC GCIH is behind you.

Roles this opens up

5
Incident Response AnalystIncident HandlerSOC Analyst (Tier 2)CSIRT AnalystDetection & Response Engineer

Who it's for

SOC analysts and security teams who own incident detection and response.

  • Guided study against the exam blueprint
  • Practice questions & mock exams
  • An instructor who has sat the exam

How we prepare you

Boot Camp

Intensive, exam-focused days with an instructor

Self-Paced

Study on your own schedule with the full curriculum

Ready to get certified?

Sit your GIAC GCIH exam with confidence.

Join the next cohort, or talk to us about sponsoring your team.