К содержимому
learnspaceYOUR NEXT CHAPTER
ПРОСТРАНСТВО ОБУЧЕНИЯ
ГлавнаяКаталог курсовМоё обучениеCoursera

Знания без границ

Учитесь у лучших университетов и компаний мира.

Открыть Coursera
Интеграция
Пространство университета
Моё пространствоСтраница курса
↵
ЯЛичный кабинетСтудент
© 2026 LearnSpaceКаждый день — возможность узнать больше.Помощь
Foundational Incident Triage and Response · LearnSpace
Назад в каталог
courseraIT и технологии

Foundational Incident Triage and Response

Курс от Coursera
Уровень не указан≈ 11 чАнглийский
О курсеНавыкиПрограммаПреподаватели

О курсе

Foundational Incident Triage and Response Build the core capabilities required for first-line incident response. In this course, you’ll practice immediate containment actions, document and escalate confirmed incidents, and execute post-containment remediation to return systems to a known-good state. You’ll also learn to spot indicators of compromise in logs, perform targeted Linux log reviews, collect TCP/IP details from hosts, and run basic SIEM queries to add context to alerts. The curriculum blends structured incident response frameworks with hands-on log analysis and SIEM fundamentals. You’ll move from the NIST/SANS incident lifecycle and documentation discipline to practical evidence collection, IOC validation with public threat intel, and initial SIEM-driven investigations across tools like Splunk, Chronicle, and Wazuh. Designed for early-career security analysts and IT professionals responsible for triage and containment, this course equips you to act quickly, document clearly, and collaborate effectively with senior responders during real incidents.

Навыки, которые вы освоите

Digital AnalysisIntrusion Detection and PreventionBusiness ContinuityCyber Threat IntelligenceSecurity Information and Event Management (SIEM)InvestigationNetwork AnalysisAnalysisDisaster RecoverySplunkDigital ForensicsData IntegrityIncident ManagementIncident ResponseEvent MonitoringData ValidationBusiness Continuity PlanningComputer Security Incident ManagementThreat Detection

Программа курса

7 модулей · 108 учебных материалов

01Start Here: Get Oriented and Check Your Skills2 материалов
Start Here: How This Skill-Based Course WorksЧтениеSkill Diagnostic: Find Your Recommended Starting PointЗадание
02Overview of Incident Response55 материалов

Incident Response

Incident Response Preparation Чтение

Учитесь у экспертов

Professionals from the Industry

Преподаватель курса

Foundational Incident Triage and Response
В каталоге вашей программы

Инвестируйте в себя

Новые знания — в удобное для вас время.

Начать на Coursera

Обучение откроется на Coursera
в новой вкладке

Обучение на Coursera

≈ 11 ч

7 модулей

Язык: Английский

Субтитры: Арабский, Французский, Украинский, Бразильский португальский, Вьетнамский, Корейский, Немецкий, Индонезийский, Турецкий, Испанский, Японский

Часть программы вашего университета
Incident Response Plan Чтение
The Incident Response Team (IRT) Видео
The Incident Response Team (IRT) Задание
Team Conditions that Support SuccessЧтение
Communication Planning Чтение
Detection, Analysis, and Escalation Чтение
Detection, Analysis, and Escalation Задание
Incident Analysis Видео
Incident Escalation, Notification and Response Чтение
Containment Чтение
Containment Задание
Eradication Чтение
EradicationЗадание
Recovery Чтение
Recovery Задание
Post-Incident Activities Чтение
Post-Incident Activities Задание
Near-Term and Long-Term Countermeasures Чтение
Security Orchestration Automation and Response Чтение
Legal and Ethical Principles Чтение
Forensic Investigations Видео
Forensic Investigations Задание
Taking Control of the Incident Scene Чтение
Taking Control of the Incident SceneЗадание
Evidence Handling Чтение
Evidence Handling Задание
Reporting of Analysis Чтение
NIST/ISO Recommendations Чтение
Reporting Findings Чтение
Reporting Findings Задание
Organization Security Policy Compliance Чтение
Organization Security Policy Compliance Задание
Emergency Response Plans and Procedures Чтение
Emergency Response Plans and ProceduresЗадание
Information Systems Contingency Planning Чтение
Business Continuity Planning Чтение
Business Impact Analysis Видео
Identify Types of Potential Disruptions Чтение
Interim or Alternate Processing Strategies Чтение
Interim or Alternate Processing Strategies Задание
Recovery Strategy SelectionЧтение
Disaster Recovery Planning (DRP)—Recovery of Information Technology Чтение
Restoration PlanningЧтение
Restoration PlanningЗадание
Backup and Redundancy Implementation Чтение
Cloud Backup and Recovery Чтение
System and Data Availability Чтение
Evaluating Alternatives Чтение
Evaluating Alternatives Задание
Testing and Drills Чтение
Testing and Drills Задание
Plan Review and Maintenance Чтение
Key TakeawaysЧтение
Incident Response and Recovery Terms and DefinitionsЧтение
03Skill Assessment 13 материалов

Lesson

Practice for Tier 1 Incident Triage Containment Escalation and Recovery DecisionsЗаданиеLearner Expectations for AssessmentЧтениеCheckpoint 1 of 3: Tier 1 Incident Triage Containment Escalation and Recovery DecisionsЗадание
04Digital Forensics 11 материалов

Digital Forensics and Investigation

Digital ForensicsВидеоData Collection and Examination ВидеоLab: Investigate Logs using Cowrie Внешний инструментReading: Handling Digital Evidence PLUGINAnalysis and Reporting ВидеоForensic Data: Data Files ВидеоReading: Digital Forensics Tools PLUGINActivity: Digital Forensics InvestigationPLUGINReading: Chances of Recovering DataPLUGINPractice Quiz: Digital ForensicsЗаданиеModule Summary and Highlights: Digital Forensics Чтение
05Skill Assessment 23 материалов

Lesson

Practice for Log and Host Evidence Triage for IOC EscalationЗаданиеLearner Expectations for AssessmentЧтениеCheckpoint 2 of 3: Log and Host Evidence Triage for IOC EscalationЗадание
06Network Traffic and Logs Using IDS and SIEM Tools31 материалов

Overview of logs

Welcome to the moduleВидеоThe importance of logs ВидеоBest practices for log collection and managementЧтениеTest your knowledge: Overview of logsЗаданиеRebecca: Learn new tools and technologiesВидеоVariations of logs ВидеоOverview of log file formatsЧтениеIdentify: Match log files to their file formatPLUGINTest your knowledge: Log components and formatsЗадание

Overview of intrusion detection systems (IDS)

Security monitoring with detection tools Видео Detection tools and techniquesЧтениеGrace: Security mindset in detection and responseВидеоComponents of a detection signature ВидеоExamine signatures with SuricataВидеоExamine Suricata logsВидео

Overview of security information event management (SIEM) tools

Reexamine SIEM toolsВидеоLog sources and log ingestionЧтениеQuery for events with SplunkВидеоQuery for events with Google SecOpsВидеоSearch methods with SIEM toolsЧтениеFollow-along guide for Wazuh setupЧтение

Review: Network traffic and logs using IDS and SIEM tools

Coach dialogue: Explore network security technologiesDIALOGUEWrap-up ВидеоGlossary: Network traffic and logs using IDs and SIEM ToolsЧтение
07Skill Assessment 33 материалов

Lesson

Practice for Initial SIEM Investigation & ReportingЗаданиеLearner Expectations for AssessmentЧтениеCheckpoint 3 of 3: Initial SIEM Investigation & ReportingЗадание
Overview of SuricataЧтение
Activity: Explore signatures and logs with SuricataВнешний инструмент
Optional Exemplar: Explore signatures and logs with SuricataВнешний инструмент
Exemplar: Explore signatures with SuricataЧтение
Test your knowledge: Overview of intrusion detection systems (IDS) Задание
Activity: Perform a query with WazuhЗадание
Test your knowledge: Overview of SIEM toolsЗадание