Students will acquire the skills necessary to successfully handle and address cybersecurity incidents. They will understand the incident response process, including preparation, detection, containment, eradication, recovery, and post-incident lessons learned. The course covers practical skills in testing and training response teams, performing threat hunting, and applying legal considerations such as due process and legal holds.
Additionally, students will gain knowledge of digital forensics, including methods for acquiring evidence from systems and memory, performing disk image acquisition, and ensuring evidence preservation. They will also learn how to document and report findings accurately, maintaining ethical standards and legal validity throughout the investigation lifecycle.
By the end of the course, students will be equipped to proactively and reactively handle security incidents, preserve evidence for legal and organizational purposes, and improve overall cybersecurity resilience.