Skip to content
normSight — Cyber Security

Defensive Trainings

CSIRT / Incident Response Training

The CSIRT / Incident Response (IHRP) course builds the ability to establish a cyber incident response team and to manage an incident end to end, from detection through containment to safe recovery.

Study at Your Own Pace

IHRP is entirely self-paced, with interactive slides students can access online without restriction. Students have lifetime access to the training materials and can take the course from home, from the office or anywhere with an internet connection.

Highly Practical

Thanks to extensive use of Hera Lab and coverage of the latest research in incident handling and response, the IHRP course is not only the most practical training course on the subject but also the most current. Apply incident response techniques against real-world networks and assets.

The Course at a Glance

  • Starting from basic incidents through to advanced incident response activities
  • Professionally analyse, manage and respond to security incidents across heterogeneous networks and assets
  • Understand the mechanics of modern cyber attacks and how to detect them
  • Use and tune open source IDS solutions (Bro, Snort, Suricata) effectively
  • Make the most of open source SIEM solutions (ELK, Splunk and others)
  • Regularly use regex and log management solutions to detect attacks
  • Detect and even proactively hunt attacks by analysing traffic, flows and endpoints, and by using analytical and tactical threat intelligence
  • Gives you access to private forums
  • Makes you a professional incident responder

Course Material

  • 10 comprehensive Hera labs
  • 13 modules
  • 4 sections

Course Delivery

  • Self-paced, HTML5, PDF, MP4
  • Offline access available
  • Access from PC, tablet and smartphone

Curriculum

  • Section: Incident Management Overview

Module 1: The Incident Management Process

The Incident Management Process module introduces you to the Preparation → Detection and Analysis → Containment, Eradication and Recovery → Post-Incident Activity cycle (the incident response lifecycle). It also addresses incident management procedures, activities and best practices for maximising effectiveness and performance and for reducing key security metrics such as time to detect, time to respond and risk points per host.

Section: Network Traffic and Flow Analysis

Module 1: Intrusion Detection Through Traffic Analysis (Part 1)

In this module you will first learn to detect attacks at the IEEE 802.x link and IP layers. Both IPv4 and IPv6 are in scope.

Module 2: Intrusion Detection Through Traffic Analysis (Part 2)

This module begins by covering how to analyse common application protocols for suspicious behaviour or anomalies. You will then learn how to make effective use of open source IDS solutions and how to tune them in order to detect real-world attacks. Snort, Bro and Suricata are addressed.

Module 3: Intrusion Detection Through Flow Analysis

In this module you will learn attack detection through flow analysis. Volumetric discovery, anomalous DNS discovery, SMB anomalies and flow visualisation are used to detect exfiltration, lateral movement, malware beacons and more.

Section: Practical Incident Management

Module 1: Preparing For and Defending Against Reconnaissance and Information Gathering

In this module you will learn all the techniques attackers use to carry out reconnaissance and information gathering, and how to prepare for and defend against them. The techniques to be detected range from Google/Shodan “hacking” through exposed OWA, JavaScript injection and SSL certificates, to DNS querying and enumeration.

Module 2: Preparing For and Defending Against Scanning

In this module you will learn all the techniques attackers use to carry out scanning activity, and how to prepare for and defend against them. The techniques covered range from war dialling and war driving to nmap/Nessus scans and WebRTC-based scanning.

Module 3: Preparing For and Defending Against Exploitation

In this module you will learn all the techniques, tactics and procedures by which attackers gain an initial foothold on a network, and how to prepare for and defend against them. The attacks covered range from passive and active sniffing, DNS cache poisoning and remote/web attacks through to abusing and brute-forcing Microsoft authentication.

Module 4: Preparing For and Defending Against Post-Exploitation

In this module you will learn all the techniques, tactics and procedures attackers use after gaining an initial foothold in order to escalate privileges and move laterally and vertically. Detection techniques such as privileged access monitoring and privilege escalation detection, anomalous system interaction monitoring, log manipulation detection, covert channel detection and persistence detection are addressed, alongside detection of RATs, attempts to identify likely attack paths, and credential reuse. Note that the full spectrum of Kerberos attacks (pass-the-hash, Kerberoasting and others) is also covered.

Section: SOC 3.0 Operations and Analytics

Module 1: SIEM Fundamentals and Open Source Solutions

In this module you will become comfortable working with some of the most effective open source SIEM solutions, such as customised ELK and Splunk.

Module 2: Logging

This module covers actionable logging, including formats, manipulation and custom parsing.

Module 3: SMTP, DNS and HTTP(S) Analytics

In this module you will see how common protocol analytics can dramatically increase your network visibility in order to detect anomalous and potentially malicious actions. More specifically, you will see how to extract actionable intrusion-related information by performing SMTP, DNS, HTTP and HTTPS analytics.

Module 4: Endpoint Analytics

In this module you will learn about the most important logs and events, correlation strategies and SIEM queries you can use to detect adversaries on your endpoints at scale. You will also see how tactical threat intelligence and adversary simulation software can help you raise your endpoint adversary detection capability. Effective use of Osquery for querying endpoints at scale is also covered.

Module 5: Baselining and Detecting Deviations

In this module you will see how baselining your environment can lead to easier, more efficient and more effective attack detection.

Prerequisites

  • Basic knowledge of networking
  • Basic knowledge of protocols
  • Basic knowledge of operating systems
  • Basic knowledge of security devices

Who Can Attend

  • SOC analysts
  • CSIRT members
  • Incident handlers
  • Incident responders
  • Red team members who want to understand blue team tactics and carry out stealthier penetration tests
  • IT security staff responsible for defending their organisation’s assets

Laboratories

The IHRP course is a practice-based curriculum. Integrated with Hera Lab, the most advanced virtual lab in IT security, this product offers an unmatched practical learning experience. Hera is the only virtual lab that provides each student with fully isolated access to every real-world network scenario on the platform. Students can access Hera Lab from anywhere over VPN.

The modules are accompanied by numerous hands-on labs in which you will be tasked with detecting:

  • Real-world attacks and malware
  • Attacks or attempted attacks at every stage of the cyber kill chain

LAB-1

Traffic Analysis Challenges (offline) — During this lab you will refresh your networking knowledge, learn to recognise TCP spoofing and internal botnet-like activity, and work to identify attacks by analysing network traffic, including IPv6-based traffic.

LAB-2

Enterprise-Wide Incident Response — Part 1: GRR — In this lab you will learn how to use the GRR incident response framework to carry out faster and more efficient IR activity. During the lab you will have the opportunity to detect malware, various stealthy persistence techniques and (unsuccessful) privilege escalation attempts on a heterogeneous, enterprise-like network.

LAB-3

Enterprise-Wide Incident Response — Part 2: Velociraptor — In this lab you will learn how to use the Velociraptor incident response framework to carry out faster and more efficient IR activity. During the lab you will be able to detect fileless malware and make use of specific Velociraptor features to proactively monitor endpoints on a heterogeneous, enterprise-like network.

LAB-4

Suricata Fundamentals — In this lab you will learn about Suricata’s capabilities, features and configuration. In addition, you will become familiar with configuring Suricata to your detection needs and learn everything about Suricata inputs and outputs. Finally, you will be shown how to parse Suricata output effectively and extract critical information.

LAB-5

Using Suricata Effectively — In this lab you will learn how to use Suricata effectively. In particular, you will first become familiar with Suricata rules and then learn how to develop your own signatures after analysing PCAP files containing malicious traffic. Suricata rules will be written to detect malicious traffic originating from ransomware, phishing attempts, trojans and malicious documents.

LAB-6

Using Bro Effectively — In this lab you will learn about Bro’s capabilities, features and architecture. In addition, you will gain knowledge of effective Bro scripting so that you can tailor Bro to your detection requirements. Finally, effective manipulation and analysis of Bro logs to extract critical information will be demonstrated.

LAB-7

Using Snort Effectively — In this lab you will learn about Snort’s capabilities, features and architecture. In addition, you will become comfortable with effective Snort rule scripting so that you can tailor Snort to your detection requirements.

LAB-8

Using Splunk Effectively (2 scenarios) — In this lab you will learn Splunk’s detection capabilities, features and architecture. The lab consists of two separate attack detection scenarios. The first will make you comfortable with writing effective Splunk searches. The second will help you understand how tactical threat intelligence can be turned into actionable Splunk searches that surface malicious activity on your network.

LAB-9

Using ELK Effectively — In this lab you will learn about ELK’s capabilities, features and architecture. You will also gain knowledge of effective ELK query writing so that you can tailor ELK to your detection and analysis requirements.

Frequently Asked Questions

What is a CSIRT?

A CSIRT is a Computer Security Incident Response Team — the function responsible for detecting, responding to and reporting cyber security incidents within an organisation. In Türkiye the equivalent structure is known as SOME.

Who is this course suitable for?

It suits security professionals, system and network administrators who will establish a CSIRT in their organisation or take a role in an existing team. Basic networking and operating system knowledge is expected.

Does it also cover setting up a CSIRT?

Yes. Team structure, role definitions, incident classification and prioritisation, response procedures and post-incident review are all in scope.

See the real risks in your systems.

Talk to our team about a penetration test or training plan that fits your scope.