Skip to main content
10151137 Incident Response
Course Information
Description
Provides an overview of the tools and techniques commonly used for detecting threats to an enterprise infrastructure. Implement strategies for documenting and reporting detected events based on industry standard compliance frameworks. We will use the Security Onion distribution. Tools include Elasticsearch, Logstash, Kibana (ELK), Suricata, Zeek, Wireshark, and TCP Dump.
Total Credits
3

Course Competencies (Course Outcomes)
  1. Analyze adversary behavior using incident response and attack frameworks
    Assessment Strategies
    Scenario Response and/or Test
    Criteria
    Classify observed activity within an incident response lifecycle
    Map observed adversary behavior to applicable MITRE ATT&CK tactics and techniques
    Differentiate normal, suspicious, and malicious activity using available context
    Prioritize investigative actions based on incident scope and business impact

  2. Analyze network traffic for indicators of compromise
    Assessment Strategies
    Skill Demonstration and/or Written Product
    Criteria
    Filter packet and session data to isolate relevant traffic
    Interpret protocol behavior to distinguish expected from anomalous activity
    Identify network indicators associated with command and control, lateral movement, or exfiltration
    Support conclusions with packet, flow, or alert evidence

  3. Analyze endpoint and system log evidence
    Assessment Strategies
    Skill Demonstration and/or Written Product
    Criteria
    Query Windows and endpoint telemetry for events relevant to an investigation
    Interpret authentication, process, file, registry, and network activity
    Correlate related events using timestamps, hosts, users, process identifiers, or other fields
    Distinguish benign administrative activity from evidence of compromise

  4. Correlate evidence across network and endpoint data sources
    Assessment Strategies
    Case Study and/or Report
    Criteria
    Combine network, host, and security monitoring evidence into a coherent sequence of events
    Resolve differences in timestamps, identifiers, and data fields across sources
    Validate significant findings using more than one evidence source when available
    Identify evidence gaps and limit conclusions to findings supported by available data

  5. Develop detection logic for suspicious activity
    Assessment Strategies
    Skill Demonstration and/or Project
    Criteria
    Construct filters, queries, or detection rules that match defined suspicious behavior
    Test detection logic against representative network or log data
    Refine detection logic to reduce irrelevant matches while preserving useful detection
    Document the behavior and evidence the detection is intended to identify

  6. Investigate the scope and root cause of a cybersecurity incident
    Assessment Strategies
    Case Study and/or Report
    Criteria
    Identify the likely initial access or triggering event from available evidence
    Determine affected hosts, accounts, services, or data within the available evidence
    Trace lateral movement, persistence, command and control, or exfiltration when present
    Distinguish confirmed findings from hypotheses and unresolved questions
    Summarize the probable root cause and progression of the incident

  7. Apply containment, eradication, and recovery strategies
    Assessment Strategies
    Scenario Response and/or Written Product
    Criteria
    Select containment actions appropriate to the observed threat and business context
    Recommend eradication actions that address identified persistence or access mechanisms
    Recommend recovery actions that restore operations while reducing reinfection risk
    Explain operational risks and tradeoffs associated with proposed response actions

  8. Evaluate endpoint security controls for incident prevention and response
    Assessment Strategies
    Skill Demonstration and/or Written Product
    Criteria
    Configure or assess endpoint controls that restrict unauthorized activity
    Verify control behavior using system or security event evidence
    Relate endpoint controls to least privilege, explicit trust, or other defensive principles
    Recommend improvements based on observed control limitations or gaps

  9. Evaluate monitoring and response practices against organizational requirements
    Assessment Strategies
    Case Study and/or Written Product
    Criteria
    Identify monitoring evidence needed to support defined security requirements
    Assess whether available logs and telemetry provide adequate visibility
    Relate incident response practices to applicable compliance or security framework expectations
    Recommend improvements to logging, monitoring, retention, or response procedures

  10. Produce professional incident response documentation
    Assessment Strategies
    Report and/or Presentation
    Criteria
    Summarize the incident for a non-technical or management audience
    Document the incident scope, evidence, timeline, and significant indicators of compromise
    Support technical conclusions with relevant and readable evidence
    Recommend remediation and follow-up actions based on investigation findings
    Cite external technical sources when they materially support investigative conclusions