Security Operations · Intermediate

Incident Response Foundations

Work a synthetic host compromise through the NIST SP 800-61 Rev. 3 lifecycle: scoping, timeline, evidence, containment and eradication under change control, verified recovery and a blameless review.

About this course

An analyst decides what an alert means. An incident responder decides what to do once something bad has actually happened — and has to do it without destroying the evidence that explains how it started or breaking the systems that still have to work. This course is the "Incident response" stage of the Defensive Security pathway, and it follows SOC Analyst Foundations (ULC-006). You work on **soc01**, an Ubuntu 24.04 lab machine that carries a **synthetic, inert compromised-host scenario**: a brute force succeeded, and the intruder left planted persistence (a systemd service and timer, a cron entry and an SSH implant key), a tampered administrative script and an inert web-shell file. Everything is generated inside your own lab from documentation-range addresses; the payload never connects anywhere, the SSH key bodies are not usable, and the "web shell" is an inert marker. No production system, SOC, or real host is ever involved. Across ten lessons you practise the lifecycle as it is actually worked, following the current revision of NIST SP 800-61 (Rev. 3, the CSF 2.0 model): triage and declaration with severity and confidence recorded separately; scoping by pivoting across authentication, web, process, socket and telemetry evidence; super-timeline reconstruction in UTC; evidence handling in order of volatility with hashes and a chain of custody; containment, eradication and recovery driven through a written change record with rollback — and graded on real host state: the planted persistence removed and the legitimate services untouched; an incident report whose confidence language matches the evidence; and a blameless post-incident review that turns the case into detection and preparation improvements. The final project hands you a fresh, unlabelled incident and asks you to work it end to end and deliver a declaration, scope, timeline, hashed evidence package, containment and recovery through change control, a report and a review — graded against a rubric and automated lab checks. It leads into Detection Engineering (ULC-111), where the lessons learned here become detections.

Content time
14 h 40 min
Lessons
10
Lab
Yes
provisioned for you
Certificate
Yes
on completion
Choose a career path

Lesson 1 is free. Enroll in a career path to access its full courses.

Lesson 1 is a free preview — read it without an account.

Security Operations — the kind of infrastructure this course is practised on

Outline

Lessons

10 lessons · 14 h 40 min
  1. Lesson 1: Events, alerts, incidents and the lifecycleFree preview

    What separates an alert from an incident, the modern incident-response lifecycle as NIST now describes it, and how to declare an incident with a severity and a confidence recorded separately.

    1 h 20 min
  2. Lesson 2: Preparation — the plan, the playbook and readiness

    The preparation that makes a response fast — an incident-response plan, playbooks, a contact tree, an evidence kit and logging readiness — and a tabletop of the case you just declared.

    1 h 15 min
  3. Lesson 3: Scoping and triage

    Pivot from the successful login across authentication, web, process, socket and telemetry evidence — and the live host — to a bounded scope statement and a weighted indicator list.

    1 h 40 min
  4. Lesson 4: Super-timeline reconstruction

    Merge authentication, web and telemetry sources — which express time three different ways — into one UTC timeline, mark the first malicious action and the persistence, and derive the dwell time.

    1 h 30 min
  5. Lesson 5: Evidence handling and chain of custody

    Collect in order of volatility, hash what you keep, and record a chain of custody another responder can verify — building an evidence package with its own manifest before anything on the host is changed.

    1 h 30 min
  6. Lesson 6: Reading persistence for containment

    Read each planted persistence artifact for exactly what it does and what removing it changes, then write a containment decision record that maps every artifact to an action, an evidence step and a risk.

    1 h 25 min
  7. Lesson 7: Containment through a change record

    Cut the intruder's persistence and return path on the live host — under a written change record with rollback, evidence captured first — while leaving nginx and the legitimate services untouched.

    1 h 40 min
  8. Lesson 8: Eradication and recovery

    Remove the payload and the web shell, recover the tampered binary from a verified known-good copy, and build a reusable verification script that proves a bundle is clean against a known-good baseline.

    1 h 35 min
  9. Lesson 9: The incident report

    Write the report that survives the incident — eight sections, observation separated from inference, a confidence word on every claim, and notification concepts explained without giving legal advice.

    1 h 30 min
  10. Lesson 10: Lessons learned and improvement

    Run a blameless post-incident review, compute the response intervals honestly, turn the case into a detection and a preparation improvement, and seal the case package.

    1 h 15 min

Hands-on

Your lab

Real virtual machines on the Ultiblob cluster, reached from your browser. You administer them; we provision and destroy them.

  1. vm-01soc01linux

Provisioned for you when you launch the lab from the course. The machines are yours for the access window; release them and launch again whenever you like.

Where it leads

Part of these career paths