Network Forensics and Incident Response

Learning objectives:
 Understand different types of forensics
 Know how to use tools for network forensics
 Understand the importance of monitoring network traffic
 Develop skills on how to collect network packets
 Develop skills on analyzing traffic and provide evidence of a network related incident or event
 Understand different phases of incident response
 Know the roles of Incident Response Team
 Develop and test security incident response plan
 Understand the necessary steps to take after the cyber security incident
 Understand the importance of integrating incident response with business continuity plan and disaster recovery plan.

 Relation to other fields of forensics
 Different types of network based evidence
 Collecting network based evidence
 Packet sniffing tools
 Analysis of captured packets of network related events
 Incident Response capability requirements
 Phases of incident response
 Roles of and Responsibilities of Computer security incident response team (CSIRT)
 Development and testing of Incident Response Plan
 Incident handling: policies and procedures
 Business Continuity and Disaster Recovery planning

Speaker Language Arabic
Content Language Englsih
Target Users  Cyber security students  Network and system administrators  Incident response professionals  Computer security incident response team (CSIRT) members  Anyone interested in building or improving their network forensics and incident management capabilities
Duration 4 Days

Pre-requisite:  Knowledge on networks  Basic knowledge on cyber security

  • D\ Abdelouahid Ahmed Derhab
    5.00 out of 5