Learning objectives
- Classify an event and prioritise an incident
- Connect observations to ATT&CK tactics and techniques
- Conduct a repeatable investigation
- Organise containment, eradication, recovery and lessons learned
Who should attend
SOC analysts, system administrators, security engineers and incident managers.
Prerequisites
Foundations in Windows and Linux systems, networking, logs and operational security.
Course outline
- SOC organisation, roles, severity levels and escalation path
- Log sources, telemetry, triage and timelines
- MITRE ATT&CK, detection hypotheses and coverage
- Endpoint, identity, network and cloud investigation
- Containment, eradication, recovery and crisis communication
- End-to-end exercise and post-incident report
Learning approach
Structured instruction, demonstrations, guided exercises, case studies and learning assessment. Technical environments are used only within an authorised context.
Reference source: MITRE ATT&CK Enterprise and NIST incident response ↗
Avnorys programme aligned with public frameworks. It does not award a MITRE or NIST certification.
Avnorys programme aligned with public frameworks. It does not award a MITRE or NIST certification.
