Курс от CourseraFoundational Incident Triage and Response Build the core capabilities required for first-line incident response. In this course, you’ll practice immediate containment actions, document and escalate confirmed incidents, and execute post-containment remediation to return systems to a known-good state. You’ll also learn to spot indicators of compromise in logs, perform targeted Linux log reviews, collect TCP/IP details from hosts, and run basic SIEM queries to add context to alerts. The curriculum blends structured incident response frameworks with hands-on log analysis and SIEM fundamentals. You’ll move from the NIST/SANS incident lifecycle and documentation discipline to practical evidence collection, IOC validation with public threat intel, and initial SIEM-driven investigations across tools like Splunk, Chronicle, and Wazuh. Designed for early-career security analysts and IT professionals responsible for triage and containment, this course equips you to act quickly, document clearly, and collaborate effectively with senior responders during real incidents.
7 модулей · 108 учебных материалов

Преподаватель курса