0%

Explore Courses Defend What Matters

Your Bag

Incident Response & Forensic Investigation

04 Digital Forensics

Incident Response & Forensic Investigation

Run a real incident from first alert to final report, coordinating containment, investigation, and recovery under pressure.

Levels
04
Skill Range
Beginner Expert
Track
Digital Forensics
Lifetime Access
Incident Response & Forensic Investigation
From 245CREDS

The technical work is only half of an incident. The other half is running it. This course follows the full lifecycle: preparation, detection and analysis, containment, eradication, recovery, and the lessons learned review that most teams skip. You will build a response plan, define severity levels that trigger the right people, and practise the decisions that matter under time pressure, including when containment costs more than the intrusion. Investigation work covers log aggregation and SIEM queries, threat hunting against a hypothesis, and correlating host, network, and identity evidence into one narrative. Communication is treated as a core skill: stakeholder updates, regulatory notification timelines, and a final report that is accurate and readable. A full simulated ransomware incident runs across the final module.

Curriculum

Learning Path

Each level is enrolled separately. Work through them in order, or start at the level that matches your experience.

  1. Level 01

    Beginner

    245 CREDS

    Purpose

    Prepare for incidents, since the response is decided before the alert fires.

    Outcome

    You can prepare an organisation to respond to an incident.

    What You'll Learn
    • Build a response plan with defined roles and severity levels.
    • Set severity thresholds that trigger the right people.
    • Prepare the tooling and access an incident will need.
  2. Level 02

    Intermediate

    488 CREDS

    Purpose

    Detect, analyse, and contain, making the decisions that matter under time pressure.

    Outcome

    You can scope and contain a live incident.

    What You'll Learn
    • Aggregate logs and query a SIEM to scope an incident.
    • Threat hunt against a hypothesis rather than at random.
    • Decide when containment costs more than the intrusion.
  3. Level 03

    Advanced

    701 CREDS

    Purpose

    Correlate evidence into one narrative and communicate it while the incident runs.

    Outcome

    You can run the investigation and communication side of an incident.

    What You'll Learn
    • Correlate host, network, and identity evidence into a single account.
    • Brief stakeholders and meet regulatory notification timelines.
    • Manage eradication and recovery without destroying the evidence.
  4. Level 04

    Expert

    1,074 CREDS

    Purpose

    Run a full incident end to end and turn it into lessons that stick.

    Outcome

    You can lead an incident from first alert to final report.

    What You'll Learn
    • Run a full simulated ransomware incident from alert to recovery.
    • Produce a final report that is accurate and readable.
    • Lead a lessons learned review that changes the next response.