DIG-FORNSC-IR.AJ1

Digital Forensics and Incident Response

Learn how to build a strong defense fabric using the latest digital forensics and incident response techniques.

  • Practice in 29 Hands-On Labs — nothing to install
  • 20 Interactive Lessons and 123 topics mapped to the official exam objectives
  • 180 Practice Test Questions

Beginner Self-paced · 1 year access

29 Hands-On LiveLabs

Practice real IT tasks in guided environments.

  • Real environments
  • Auto-graded
  • No installation
20Interactive Lessons
123Topics
29LiveLab
180Practice Test Questions
94Flashcards
94Glossary of terms

01 / Skills you'll get

What you will be able to do

Try Free → No credit card required
In this course, you’ll acquire specialized skills to identify and reconstruct a cybersecurity incident by collecting and analyzing digital evidence to persecute the threat actor. The digital forensics incident response solutions like threat hunting will help you capture the root cause of an attack and remove all traces of it from your network. Once enrolled, you’ll gain access to risk-free simulation labs to practice your theoretical knowledge and gain practical experience to add to your resume! So what are you waiting for? Everything you need is available in this hot-selling training courseware.
  • Engage and manage IR teams, utilizing Security Orchestration, Automation, and Response (SOAR). 
  • Apply various incident investigation analyses to understand the cyber kill chain and the diamond model of intrusion analysis.
  • Collect and analyze network evidence from firewalls, proxy logs, NetFlow, and packet captures using tools like Wireshark. 
  • Take actions to respond to ransomware incidents and investigate cyberattacks. 
  • Set up and use malware sandboxes for static and dynamic analysis using tools like ClamAV and YARA.
  • Source and leverage threat intelligence using the MITRE ATT&CK framework.
  • Work with Indicators of Compromise (IOCs) and Indicators of Attack (IOAs).
  • Create hypotheses, plan and execute threat hunts, and apply digital forensic techniques and EDR tools for threat hunting.
  • Manage and analyze log files using SIEMs and other tools, with a focus on Windows Event Logs.

Course Highlights

  • 20 Structured Lessons Comprehensive coverage of core course objectives
  • 29 Hands-On LiveLabs Interactive guided scenarios with instant evaluation
  • 180 Practice Questions Assessment tests with detailed answer rationales
  • 1 Year Full Access Self-paced learning accessible anytime on all devices

02 / Lessons & labs

See exactly what you will learn and practice

Download outline (PDF)

Lessons

20 Interactive Lessons · 123 topics
01 Preface 3 topics
  • Who this course is for
  • What this course covers
  • To get the most out of this course
02 Understanding Incident Response 7 topics
  • The IR process
  • The IR framework
  • The IR plan
  • The IR playbook/handbook
  • Testing the IR framework
  • Summary
  • Further reading
03 Managing Cyber Incidents 7 topics
  • Engaging the incident response team
  • SOAR
  • Incorporating crisis communications
  • Incorporating containment strategies
  • Getting back to normal – eradication, recovery, and post-incident activity
  • Summary
  • Further reading
04 Fundamentals of Digital Forensics 6 topics · 1 LiveLab
  • An overview of forensic science
  • Locard’s exchange principle
  • Legal issues in digital forensics
  • Forensic procedures in incident response
  • Summary
  • Further reading

1 LiveLab in this lesson — see the labs panel →

05 Investigation Methodology 6 topics · 1 LiveLab
  • An intrusion analysis case study: The Cuckoo’s Egg
  • Types of incident investigation analysis
  • Functional digital forensic investigation methodology
  • The cyber kill chain
  • The diamond model of intrusion analysis
  • Summary

1 LiveLab in this lesson — see the labs panel →

Hands-On Labs Our edge

29 LiveLabs
  • Completing the Chain of Custody
  • Performing Reconnaissance on a Network
  • Installing a DHCP Server
  • Performing a Proxy Server Operation
  • Creating a Firewall Rule
  • Capturing Packet Using RawCap
Labs run in your browser — nothing to install.

03 / FAQs

Questions before you start

Contact us ↗
What is digital forensics and incident response?  
Digital forensic and incident response (DFIR) is a specialized field of cybersecurity that collects and analyzes digital evidence to mitigate a threat incident in a timely approach. 
Are there any prerequisites for this course? 
No, there are no formal requirements to take this course. However, a basic understanding of cybersecurity, threats, and incident response will help you get started smoothly
What tools and software will I learn to use in this cybersecurity forensic course?  

You will learn to use the following tools:

Incident Response Tools:

  • SOAR (Security Orchestration, Automation, and Response)
  • Network Evidence Collection and Analysis:
  • Firewalls
  • Proxy logs
  • NetFlow
  • Packet capture
  • Wireshark
  • RawCap
  • tcpdump
  • NetworkMiner

Host-Based Evidence Collection and Analysis:

  • WinPmem for memory acquisition
  • FTK Imager
  • Velociraptor
  • EnCase Imager
  • Volatility (for memory analysis)
  • Strings (Linux tool)

Digital Forensics Platforms and Tools:

  • Forensic platforms
  • Autopsy
  • Master File Table analysis tools
  • Prefetch analysis tools
  • Registry analysis tools

Log Analysis:

  • SIEMs (Security Information and Event Management systems)
  • Windows Event Logs
  • DeepBlueCLI

Malware Analysis:

  • Malware sandbox
  • ClamAV
  • YARA
  • VirusTotal
  • Process Explorer

Threat Intelligence and Threat Hunting:

  • MITRE ATT&CK framework
  • Maltego
 How much does a digital forensics and incident response specialist make in a month?
The salary of a Digital Forensics and Incident Response Specialist can vary depending on factors such as experience, location, and specific job roles. As of 2024, the average salary for a Digital Forensics Investigator in the United States is around $74,000 to $110,000 per year​.

Get Hands-on! Get DFIR Skills! 

Discover how to use advanced DFIR tools and frameworks to build a strong network security infrastructure.

  • 1 year of full access
  • 29 LiveLab included
  • Certificate of completion
Try Free

No credit card required

scroll to top