Visão Geral
Este curso apresenta os fundamentos de resposta a incidentes de segurança, abordando preparação, detecção, triagem, contenção, erradicação, recuperação e documentação.
Conteúdo Programatico
Module 1: Incident Response Fundamentals
- Incident response concepts
- Incident lifecycle
- Incident response teams
- Incident classification
- Severity assessment
- Incident response plans
- Roles and responsibilities
- Communication
- Escalation
- Incident response governance
Module 2: Detection and Triage
- Security alerts
- Alert validation
- Incident identification
- Initial triage
- Evidence collection
- IOC identification
- Threat classification
- Incident prioritization
- Investigation scope
- Triage documentation
Module 3: Investigation
- Timeline analysis
- Log investigation
- Endpoint investigation
- Network investigation
- Identity investigation
- Malware indicators
- Credential attacks
- Lateral Movement
- Persistence
- Attack reconstruction
Module 4: Containment
- Containment strategies
- Host isolation
- Account containment
- Network containment
- Credential reset
- Malicious process containment
- Persistence containment
- Short-term containment
- Long-term containment
- Containment validation
Module 5: Eradication and Recovery
- Malware removal
- Persistence removal
- Credential remediation
- Vulnerability remediation
- System recovery
- Identity recovery
- Security control restoration
- Recovery validation
- Monitoring after recovery
- Business continuity
Module 6: Evidence and Documentation
- Evidence handling
- Evidence preservation
- Chain of custody
- Investigation notes
- Timeline documentation
- IOC documentation
- Technical reporting
- Executive reporting
- Incident records
- Lessons learned
Module 7: Incident Response Tools
- SIEM
- EDR
- Network monitoring
- Threat intelligence
- Forensics tools
- Log analysis
- Case management
- Evidence collection tools
- Investigation workflows
- Tool integration
Module 8: Practical Incident Response
- Incident identification
- Initial triage
- Evidence collection
- Investigation
- Containment
- Eradication
- Recovery
- Reporting
- Lessons learned
- Incident response case study