Cyber Incident Response
&
and Penetration Testing
An incident response plan is a documented, written plan with 6 distinct phases that helps IT professionals and staff recognize and deal with a cybersecurity incident like a data breach or cyber attack. Properly creating and managing an incident response plan involves regular updates and training. This course is designed to do just that. This course is focused on the practical side of penetration testing as well as the theory behind it.
Duration
2 days
Course Outcome
- Have a high level overview of the response process
- Understand the 6 phases of an incident response plan
- Effectively prioritize the response to a security incident
- Build a computer security incident response team (CSIRT)
- Develop an incident response action plan
- Post-incident activity
- Understand the GDPR
- Detect ARP poisoning and protect your self and your network against it.
- Use more than 20 penetration testing tools such as ettercap, wireshark, aircrack-ng suit ...etc.
- Combine individual attacks to launch even more powerful attacks.
- Perform Penetration Testing
- Perform Reverse Engineering for Forensics
- Take necessary measures to prevent cyber attacks
- Secure networks
Prerequisites
- Basic understanding of the current cybersecurity ecosystem
- Basic understanding of analysis of hacks on computers and networks
- Basic understanding of Risk Management
- Basic linux (preferably debian build such as kali)
Outline
- Threat modeling
- Building a CSIRT
- The Phases of IRP
- Preparation
- Identification
- Containment
- Eradication
- Recovery
- GDPR Standard
- GDPR Incident Response Methodologies
- Industry specific use case
- Penetration Testing
- SQL injections
- Burp Suite
- XSS
- File upload Vulnerability
- Command Line Execution
- Havij
- Reverse Engineering
- Software Hacking
- Virus illustration
- Firewall Bypassing
- Prevention & Security
- Securing Your Network From The Above Attacks
- How to Configure Wireless Security Settings To Secure Your Network
- Detecting ARP Poisoning Attacks
- Detecting Suspicious Activities using Wireshark
- Assessment
NOTE: This course requires lab.
Practical, connected learning
My wider training approach brings hands-on implementation and systems thinking together, connecting technology with real operational needs.