Master the IR lifecycle, forensic investigation phases, evidence collection, and analysis tools based on NIST SP 800-61.
Record of evidence handling from collection through presentation in court. Documentation reinforces integrity.
Bit-for-bit copy of storage media used for analysis. Original evidence remains preserved.
Generate file hashes to detect unintended changes and verify evidence integrity.
Snapshot of RAM contents capturing running processes, passwords, and volatile data.
Security Information & Event Management — aggregates logs and correlates events across sources
Security Orchestration & Automated Response — uses playbooks for automated remediation
Creates log entries when rules match. Outputs: Unified, Syslog, CSV, Tcpdump
File Integrity Monitoring — detects unauthorized changes to critical files
Data Loss Prevention — enforces data classification and transfer policies
Network flow analysis — metadata and statistics about traffic patterns