01 - Introduction to Incident Response
Effective incident response requires a structured approach. The most widely adopted framework is defined in **NIST Special Publication 800-61 Revision...
02 - Incident Triage and Containment
When an alert fires or an incident is reported, the immediate goals are to determine its validity, scope the impact, and stop the adversary from movin...
03 - Web and Cloud Incident Playbooks
This section outlines specific step-by-step procedures for common web and cloud incidents.
04 - Forensic Analysis and Memory Dumps
Forensic analysis involves examining digital media in a forensically sound manner to identify, preserve, recover, analyze, and present facts and opini...
05 - Post-Incident Activity and Lessons Learned
The post-incident phase is arguably the most important for improving an organization's security posture over time. Failing to learn from an incident g...
06 - Hands-On Lab: Web Server Incident Triage
In this lab, you will act as a first responder. You have received an alert about suspicious activity on a web server. You will use a Python script to ...
07 - References and Further Reading
To deepen your understanding of Incident Response, refer to the following industry standards, frameworks, and tool documentation.
Incident Response Playbook
Welcome to the Incident Response Playbook. This guide provides a comprehensive framework for preparing for, detecting, analyzing, and recovering from ...