Incident Handlers need a diverse set of technical skills in their jobs.
Applied Incident Response provides a concise review of each stage and skill in incident handling that will benefit new incident handlers and experienced professionals looking for a refresher or reference. Some of what incident handlers will learn includes:
- Incident readiness including planning with a framework such as NIST SP 800-61
- Response and triage
- Acquiring memory including VMs and protecting your credentials
- Imaging physical and logical disks
- Collection and storage of network data and tools in the Security Onion Linux Distribution
- Event log analysis
- Memory analysis
- Malware analysis using Cuckoo and Mandingo
- Disk forensics
- Continuous improvement of incident readiness
- Threat hunting
- Adversary emulation with Caldera