Incident Response: Network Analysis
Walking into an incident response situation can be intimidating. This course will teach you how to analyze the network data, correlate network artifacts, and begin to piece together the story of what happened.
In an incident response scenario, gathering artifacts for analysis can be stressful. In this course, Incident Response: Network Analysis, you’ll learn how to analyze network artifacts in a compromised environment. First, you’ll take the initial indicators from an attack and pull out relevant artifacts. Next, you’ll correlate these artifacts with other phases of the attack chain, working backwards to tell the story of what happened. Finally, you’ll broaden your search to look for additional lanes of compromise and determine the incident’s full scope. When you’re finished with this course, you’ll have the skills necessary to operate as an incident response network analyst and understand how to synchronize with the other phases of incident response.
Author Name: Brandon DeVault
Author Description:
Brandon DeVault is a Security Researcher focused on threat hunting at CrowdStrike. He is also a member of the Florida Air National Guard with a variety of offensive and defensive experience. Prior to joining CrowdStrike, Brandon worked full-time as an author with Pluralsight and at Elastic, creating and delivering security content. He also worked with Special Operations Command, where he had two deployments to Afghanistan on deployable communications teams. His experience spans incident response… more
Table of Contents
- Course Overview
1min - Creating the Story
3mins - Ransomware Communication
22mins - Lateral Movement
17mins - Ground Zero
7mins - Network Enumeration
8mins - Additional Lanes
9mins
There are no reviews yet.