Advanced Incident Response Threat Hunting and Digital Forensics

RegisterInquiry
Advanced Incident Response Threat Hunting and Digital Forensics
Loading...

CI3952

Madrid (Spain)

14 Sep 2026 -02 Oct 2026

6145

Overview

Introduction:

Advanced incident response with threat hunting and digital forensics represents an integrated cybersecurity discipline that governs the detection, investigation, and interpretation of sophisticated cyber threats within enterprise environments. It encompasses the analysis of adversary behavior, attack techniques, digital evidence, and compromise indicators through structured investigative and forensic processes. This training program covers advanced incident response frameworks, threat hunting methodologies, digital forensic models, identity analysis, cloud investigations, and network based detection approaches that support modern security operations. It presents an integrated perspective on correlating multi-source evidence, reconstructing attack lifecycles, and strengthening organizational detection and response capabilities across complex technology environments.

Program Objectives:

By the end of this program, participants will be able to:

  • Analyze advanced incident response and threat hunting frameworks within enterprise environments.

  • Evaluate endpoint, identity, cloud, and network based investigation models.

  • Assess multi-source forensic evidence and attack chain reconstruction structures.

  • Examine adversary behavior patterns and threat detection methodologies.

  • Explore integrated detection, response, and investigative frameworks across security operations.

Target Audience:

  • Incident response teams.

  • SOC analysts and threat hunters.

  • Digital forensics investigators.

  • Cybersecurity engineers.

  • Professionals managing security operations.

Program Outline:

Phase 1: Endpoint Internals and Forensic Acquisition.

Day 1:

OS Internals and Process Analysis:

  • Windows and Linux internals including processes, threads, and system calls.

  • Process relationships and execution hierarchy.

  • SVCHOST architecture and service grouping behavior.

  • Inter-process communication, named pipes, and IPC mechanisms.

  • Behavioral indicators distinguishing normal and malicious processes.

Lab Exercises:

  • Build and analyze complex process trees reflecting malicious activity.

  • Investigate abnormal SVCHOST behavior using system and event logs.

Day 2:

Memory and Registry Forensics:

  • Registry architecture and persistence mechanisms.

  • Autorun entries and service-based persistence.

  • Memory acquisition concepts and runtime artifacts.

  • RPC communication and client-server bindings.

  • Indicators of system call manipulation and hooking.

Lab Exercises:

  • Analyze registry autorun persistence mechanisms.

  • Identify syscall hooking patterns.

  • Trace RPC activity within system logs.

Day 3:

Volatile Data Acquisition:

  • Forensic principles including chain of custody and timestamp preservation.

  • Classification of volatile data sources.

  • Prioritization of memory, network, and cache artifacts.

  • Data acquisition integrity within live systems.

  • Impact of volatile data on incident reconstruction.

Lab Exercises:

  • Capture volatile data from an infected environment using KAPE, Velociraptor, or FTK Imager.

  • Validate integrity and preservation of collected data.

Day 4:

Disk Artifact Analysis:

  • File system structures NTFS and ext4 and metadata analysis.

  • Timeline construction using file system artifacts.

  • Raw data parsing concepts and interpretation.

  • Malware file structures and executable formats.

  • Correlation between disk artifacts and attack activity.

Lab Exercises:

  • Perform raw data parsing on acquired disk images.

  • Extract and analyze a malware sample using hex-level inspection.

Phase 2: Identity, Active Directory and Logging:

Day 5:

Authentication Protocols and Identity Flow:

  • Authentication mechanisms including Kerberos, NTLM, OAuth2, and SAML.

  • Token issuance and validation processes.

  • Federation and identity trust relationships.

  • Authentication flows and failure points.

  • Indicators of authentication abuse.

Lab Exercises:

  • Simulate Kerberos TGS request behavior.

  • Analyze authentication logs and Event ID 4769.

Day 6:

Active Directory Attack Path Analysis:

  • Active Directory architecture and trust relationships.

  • Privilege escalation pathways within AD environments.

  • Group Policy structures and security implications.

  • Attack methodologies including DCsync and DCShadow.

  • Graph based analysis of privilege relationships.

Lab Exercises:

  • Use BloodHound to map attack paths from low privilege to domain control.

  • Identify DCsync and DCShadow indicators in logs.

Day 7:

Credential Theft and Abuse Detection:

  • Credential theft techniques including Kerberoasting and Pass-the-Hash.

  • Authentication anomalies within enterprise systems.

  • Correlation between identity events and attack activity.

  • Endpoint and EDR based detection indicators.

  • Attack patterns targeting identity infrastructure.

Lab Exercises:

  • Detect Kerberoasting and Pass-the-Hash activity in security logs.

  • Analyze authentication anomalies across systems.

Day 8:

Log Correlation and Persistence Analysis:

  • Critical Windows Event IDs including 4624, 4688, and 7045.

  • Process lineage and event correlation.

  • Persistence mechanisms within system logs.

  • Integration of EDR telemetry with event logs.

  • Multi-source correlation for attack reconstruction.

Lab Exercises:

  • Build lateral movement chains using correlated event logs.

  • Identify persistence mechanisms through registry and process artifacts.

Phase 3: Cloud and Network Threat Hunting:

Day 9:

Azure and M365 Identity Threat Hunting:

  • Azure AD and Microsoft 365 identity structures.

  • Identity roles and access control models.

  • Conditional access policies and failure scenarios.

  • Behavioral anomalies in identity usage.

  • Indicators of identity compromise.

Lab Exercises:

  • Detect impossible travel scenarios.

  • Analyze conditional access misconfigurations in Azure AD logs.

Day 10:

AWS Security and Activity Analysis:

  • AWS identity and access management structures.

  • Role and policy relationships within cloud environments.

  • CloudTrail logging and activity monitoring.

  • Persistence mechanisms within AWS environments.

  • Data exfiltration patterns within cloud systems.

Lab Exercises:

  • Analyze CloudTrail logs for abnormal API activity.

  • Detect unauthorized key creation and logging disablement.

Day 11:

Network Flow Analysis and C2 Detection:

  • Network traffic structures including PCAP, NetFlow, and Zeek.

  • Command and control communication patterns.

  • Beaconing behavior and frequency analysis.

  • DNS tunneling and domain generation algorithms.

  • Encrypted traffic anomalies and covert channels.

Lab Exercises:

  • Identify command and control beaconing in network flow data.

  • Detect DGA patterns in DNS logs.

  • Analyze DNS over HTTPS DoH activity.

Day 12:

Web Application and Database Log Analysis:

  • Web server log structures including Apache and IIS.

  • Application-layer attack patterns.

  • Database query behavior and anomalies.

  • Data exfiltration indicators within application logs.

  • Correlation between web activity and compromise events.

Lab Exercises:

  • Analyze web server compromise scenarios.

  • Detect SQL injection attempts through log analysis.

  • Identify abnormal database query patterns and exfiltration traces.

Phase 4: Detection Engineering and Capstone:

Day 13:

Threat Intelligence and Detection Development:

  • Threat intelligence lifecycle and data sources.

  • Indicators of compromise and behavioral detection.

  • Intelligence enrichment and contextualization.

  • Detection logic and rule structuring.

  • Relationship between intelligence and detection capability.

Lab Exercises:

  • Enrich indicators using threat intelligence feeds.

  • Develop behavioral detection rules using YARA or Sigma.

Day 14:

Detection Coverage and Optimization:

  • Mapping adversary behavior to detection frameworks.

  • Detection coverage evaluation using ATT&CK.

  • Alert tuning and false positive reduction.

  • Malware structure and signature characteristics.

  • Detection gap identification within environments.

Lab Exercises:

  • Conduct detection gap analysis for simulated attacks.

  • Propose improvements to detection logic and alerting.

Day 15:

Capstone Incident Response Exercise:

  • Full attack lifecycle reconstruction.

  • Correlation of endpoint identity cloud and network evidence.

  • Identification of initial access lateral movement and persistence.

  • Detection and containment gap analysis.

  • Reporting structures and timeline development.

Lab Exercises:

  • Perform full incident investigation across all data sources.

  • Produce complete timeline analysis and summary report.