Incident Response
Move from a confirmed alert into structured response: validate, scope, preserve evidence, contain, eradicate, recover — and report to both engineers and executives. Recommended prior knowledge: Cyber Foundations or SOC Analyst L1.
What you will be able to do
- Validate and scope an incident from multi-source evidence, preserving what matters before acting.
- Choose defensible containment, eradication and recovery actions, in the right order, with business impact in mind.
- Produce the incident timeline, technical summary and executive summary a real response requires.
Units
- 01
Incident Response Foundations
What makes an event an incident, the response lifecycle, severity, roles, and the one rule that governs everything: evidence is preserved before it is disturbed.
BeginnerAvailableWhy you are learning this
Every response decision later in this path assumes you can classify what you are looking at and know which lifecycle phase you are in.
- 02
Detection & Analysis
Turning an alert into a validated incident: scoping, blast radius, impact analysis, timeline construction and disciplined IOC handling.
BeginnerAvailableWhy you are learning this
Responders who contain before they scope contain the wrong thing. This module builds the analysis discipline that makes every later action defensible.
Unit contents7
Theory Lessons(6)
Practical Labs(1)
- 03
Containment
Short-term versus long-term containment, isolation and account decisions, what must be preserved first, and communicating while the incident is still live.
BeginnerAvailableWhy you are learning this
Containment is where response decisions become irreversible. This module trains the judgment those minutes demand.
Unit contents7
Theory Lessons(6)
Practical Labs(1)
- 04
Eradication & Recovery
Root cause, persistence removal, recovery validation, lessons learned and the post-incident actions that stop the same incident from recurring.
Job-ReadyAvailableWhy you are learning this
An incident closed without eradication is an incident scheduled to reopen. This module is the difference between resolving and postponing.
- 05
Incident Types in Practice
Applying the lifecycle to the incidents responders actually meet: credential compromise, endpoint malware, phishing, web compromise, lateral movement and data-access incidents, with cloud awareness.
Job-ReadyAvailableWhy you are learning this
Each incident type bends the same lifecycle differently — knowing where each one bends is what makes an experienced responder fast.
Unit contents7
Theory Lessons(6)
Practical Labs(1)
- 06
Communication, Reporting & Command
Chain of evidence, documentation discipline, technical versus executive communication, response metrics, incident-commander awareness — and the integrated Marasi Logistics capstone.
Job-ReadyAvailableWhy you are learning this
A response that is not documented and communicated did not happen, as far as the organization is concerned. This module closes the loop — then proves it in the capstone.
Unit contents7
Theory Lessons(6)
Practical Labs(1)
Recommended next
Threat Hunting
Proactive, hypothesis-driven investigation — finding attacker behavior the alerts missed, and turning what you find into new detections. Recommended prior knowledge: Cyber Foundations or SOC Analyst L1.
SOC Analyst L2
Step up from Tier-1 triage to Tier-2 depth: correlate across sources, hunt on a hypothesis, engineer and tune detections, and lead complex investigations. Recommended after completing SOC Analyst L1.