Rabat, MoroccoOn-site · Virtual classroom · Corporate training
contact@avnorysacademy.com

Defensive cybersecurity

Blue Team and incident response

Structure detection, investigation, containment and lessons learned for realistic incidents.

Learning objectives

  • Classify an event and prioritise an incident
  • Connect observations to ATT&CK tactics and techniques
  • Conduct a repeatable investigation
  • Organise containment, eradication, recovery and lessons learned

Who should attend

SOC analysts, system administrators, security engineers and incident managers.

Prerequisites

Foundations in Windows and Linux systems, networking, logs and operational security.

Course outline

  • SOC organisation, roles, severity levels and escalation path
  • Log sources, telemetry, triage and timelines
  • MITRE ATT&CK, detection hypotheses and coverage
  • Endpoint, identity, network and cloud investigation
  • Containment, eradication, recovery and crisis communication
  • End-to-end exercise and post-incident report

Learning approach

Structured instruction, demonstrations, guided exercises, case studies and learning assessment. Technical environments are used only within an authorised context.

Reference source: MITRE ATT&CK Enterprise and NIST incident response ↗
Avnorys programme aligned with public frameworks. It does not award a MITRE or NIST certification.