TrainingSecurity / SecurityETC-FOR
ETC-FORCloudTeam course
System Forensics, Incident Handling and Threat Hunting (FOR)
An intensive advanced training covering incident handling, digital forensics, network security, and memory/storage analysis. The course includes numerous hands-on exercises on Windows internals, memory analysis, malware handling, network forensics, timeline building, and digital evidence reporting. Participants learn to identify, collect, and preserve data correctly, analyze it, and investigate security incidents.
- Duration
- 5 days
- Level
- Advanced
- Provider
- In-house courses
- Topic
- Security / Security
Course outline
- Introduction to Incident Handling
- Incident Response and Handling Steps
- Windows Internals
- Handling Malicious Code Incidents
- Network Forensics and Monitoring
- Securing Monitoring Operations and Evidence Gathering
- Memory: Dumping and Analysis
- Memory: Indicators of Compromise
- Disk: Storage Acquisition and Analysis
- Reporting – Digital Evidence
Skills you will gain
- Identifying and prioritizing security incidents
- Applying incident response and handling procedures according to best practices
- Analyzing Windows internals and gathering data from a running operating system
- Detecting and handling malicious code incidents
- Performing network forensics and detecting intrusion patterns
- Creating and analyzing memory dumps
- Detecting indicators of compromise using Yara rules
- Analyzing storage media, including NTFS file system, and recovering deleted data
- Building event timelines and reporting digital evidence
Who should attend
- IT professionals
- Forensics and Incident Handling Specialists
- Security Consultants
- Enterprise Administrators
- Infrastructure Architects
- Security Professionals
- Systems Engineers
- Network Administrators
- Other people responsible for implementing network and perimeter security
Prerequisites
- Good hands-on experience in administering Windows infrastructure
- At least 8 years in the field recommended
Upcoming dates
These sessions run online with LLPA partners. Times are shown in Polish time, and the language of delivery is listed for each date.
| Date | Times (Polish time) | Language | Status | Price | Action |
|---|---|---|---|---|---|
| 09:00–17:00 | English | Scheduled | 15730 PLN | Request a quote |
15730 PLN
Ask about dates