Description
This two-day course provides a comprehensive introduction to cybersecurity, security incident management and the fundamentals of digital forensics. It focuses on understanding modern threats, attack methodologies and techniques for detection, containment, and analysis within an organizational environment. The course is intended for IT professionals, system administrators, security and SOC team members, as well as anyone seeking to gain an understanding of cybersecurity and forensic processes or to enhance existing knowledge. The course combines theoretical concepts with practical examples, with emphasis on attack methodologies (Kill Chain and MITRE ATT&CK), SOC operations, Windows system analysis and the implementation of encryption and security controls. Through practical scenarios, participants learn to identify indicators of compromise, analyse logs, respond in the early stages of incidents, and properly handle digital evidence. Special emphasis is placed on the incident lifecycle—from detection and initial response to forensic analysis and prevention. Additional topics include Windows artifacts, applied cryptography and security operations such as privilege management, patch management and continuous system monitoring. Upon completion, participants will understand the full incident management lifecycle, apply fundamental forensic principles and implement key security measures in an organizational environment.
Prerequisites