Skip to main content

DFIR 360 - Incident Response & Practical Forensics

February 1st, 2nd & 3rd
Intermediate

DFIR 360 - Incident Response & Practical Forensics

Description

This intensive, hands-on masterclass consolidates the core pillars of modern Digital Forensics and Incident Response into a single, cohesive curriculum. Designed to equip you with the essential methods and tools required to handle security incidents, this course bridges the gap between raw data acquisition, deep-dive operating system forensics, and rapid malware triage. Through practical scenarios, you will transition from initial triage to advanced offline analysis, before dissecting the very threats that triggered the response. Key learning objectives: - Master the critical phases of RAM and hard disk acquisition, and learn how to conduct efficient live analysis and surgical triage under pressure to capture volatile evidence before it is lost. - Delve into the heart of the Windows artefacts and the NTFS file system to reconstruct threat actor activity. - Move from live systems to dead-box forensics, analyzing acquired images to uncover hidden footprints, persistence mechanisms, and lateral movement. - Complement your forensic investigations with basic malware analysis techniques (both static and dynamic approaches) to quickly assess the threat level of suspicious Windows executables and Office documents. Who should attend: - This course is designed for security professionals (from IT System & Network Administrators to Incident Responders) who want to build a solid, end-to-end understanding of forensic investigations from the first alert on a compromised host to the final analysis of the payload.

Course Level

Intermediate

Course Requirements

Please bring your own laptop (no special administrative rights are required, but you need to be able to connect to a lab VM through RDP) and a strong dose of curiosity and perseverance. :-)

Key takeaways

End-to-end investigation (run complete, autonomous investigations from the first alert to final payload analysis) Evidence acquisition (master RAM and disk collection while strictly maintaining the chain of custody) Windows artifacts dissection (dive into NTFS metadata and OS artifacts to trace threat actor activity) Timeline reconstruction (map out system execution history, file deletions, and lateral movement) Malware triage (perform static and dynamic analysis to extract actionable IoCs from Windows executables and Office documents)

Speaker

Suggested sessions