Incident Response & Digital Forensics
Faculty Profiles

Konstantin Sapronov
Head of Global Emergency Response Team at Kaspersky

Ayman Shaaban
Senior Security Researcher at Kaspersky
Course length
Duration
Total hours
Credits
Language
Course type
Fee for single course
Fee for degree students
Skills you’ll learn
Overview
In a world where cyber attacks are discovered every day, skills such as responding to security incidents, conducting initial live analysis of compromised computer to detect threats, collecting digital evidences in forensically sound environment and analysing collected evidences to uncover the attack scenario, are no longer optional. All of these skills are highly required for security professionals to face the well organised cyber attacks which targets institutions regardless of their business type; financial, governmental or industrial.
In this course we will provide the knowledge needed to assemble different types of evidence properly, and walk through the various stages of the analysis process.
Learning highlights
- This course will fully introduce attendees to incident response and digital forensics. The hands-on, practice-oriented format of this course will allow students to obtain the required skills to conduct the cycle of detection, response and analysis of compromised systems, in both live and postmortem situations, with best practices to discover different cyber attacks.
- We will start by discussing the principles of incident response and digital forensics processes and move on to learning about the approaches that are used to conduct evidence collection and analysis. We will study various tools to perform evidence collection and live analysis, and go through different techniques to analyse volatile and nonvolatile data. We also will talk about data recovery and learn how to use multiple tools to perform registry and system logs analysis.
- Next, we will be taught how to build a timeline of all operating system activities and how to analyse browsers artifacts and e-mails clients, then go on to extract data from a computer’s memory and investigate network traffic.
Course outline
4 classes
Incident Response foundations
Basic terms and definitions of IR. Nature of cyber attacks. Used cases.
Incident Response foundations
Lifecycle of cyber incident. IR process.
Preparation to IR.
Incident Detection and Initial Response
Monitoring and initial analysis of suspicious alerts. Verification and assessment of incidents. Basic indicators of compromise
Data Collection
Evidence acquisition. Disk’s imaging.
Dump of memory. Network traffic capturing.
Prerequisites
This course is one of three in a wholistic series.
Students that have already taken MSL-111 and those with prior experience with HTML, CSS, and Javascript building simple web pages will be good candidates for this module.
With an educational background in FInancial and informatics in technical systems Management, Konstantin has had an extensive career in cyber security. Starting in 2001, he worked for Kaspersky in Moscow, steadily taking on more tasks, from Non-Intel Threats Research Group Manager to Head of Virus Lab APAC in China.
With over 15 years of IT technologies experience, mostly in security fields, and more than ten years in the AntiVirus field, he now is the Head of Global Emergency Response Team.
See full profileIn 2009, after his BSc in communication and electronics, Ayman finished his cyber security education at Information Technology Institute (ITI), Intake 29, Egypt. His career as digital forensics engineer with the National Telecommunication Regulatory Authority in the Egyptian Computer Emergency Response Team division, EG-CERT, followed shortly after in the same year.
In 2014 he started at Kaspersky and moved up to a Senior Security Researcher in the Global Emergency Response Team, R+D. He has published several times, from a book he co-authored “Practical Windows Forensics” to articles such as “Mobile Phone Forensics”.
See full profileApply for this course
Incident Response & Digital Forensics
by Konstantin Sapronov, Ayman Shaaban
Total hours
45 Hours
Dates
Apr 09 - Apr 27, 2018
Fee for single course
€1500
Fee for degree students
€750
How to secure your spot
Complete the form below to kickstart your application
Schedule your Harbour.Space interview
If successful, get ready to join us on campus
FAQ
Will I receive a certificate after completion?
Yes. Upon completion of the course, you will receive a certificate signed by the director of the program your course belonged to.
Do I need a visa?
This depends on your case. Please check with the Spanish or Thai consulate in your country of residence about visa requirements. We will do our part to provide you with the necessary documents, such as the Certificate of Enrollment.
Can I get a discount?
Yes. The easiest way to enroll in a course at a discounted price is to register for multiple courses. Registering for multiple courses will reduce the cost per individual course. Please ask the Admissions Office for more information about the other kinds of discounts we offer and what you can do to receive one.