When a breach happens, the first few hours decide how much damage it does. This advanced course trains you to lead incident response end to end: containing active threats, preserving forensic evidence, and reverse-engineering malware samples to understand what an attacker actually did. You’ll work through real malware families in a sandboxed lab and build the reporting skills IR teams rely on under pressure.
What You Will Learn
- Contain and eradicate active threats during a live incident
- Preserve forensic evidence following chain-of-custody standards
- Reverse-engineer malware samples in an isolated sandbox
- Extract indicators of compromise and map attacker behavior
- Write executive-ready incident and forensic reports
Course Curriculum
The program covers incident handling and containment, digital forensics fundamentals, static and dynamic malware analysis, and a capstone breach investigation combining all three disciplines under time pressure.
What You Will Learn
- Lead containment on a live, simulated breach
- Preserve evidence to forensic chain-of-custody standards
- Reverse-engineer real malware samples safely in a sandbox
- Map attacker behavior to threat intelligence frameworks
- Deliver reports that satisfy both technical and executive audiences
Tools & Technologies Covered
- Volatility
- Ghidra
- YARA
- Sysinternals Suite
- Cuckoo Sandbox

