Security Operations · Intermediate
Incident Response Foundations
Work a synthetic host compromise through the NIST SP 800-61 Rev. 3 lifecycle: scoping, timeline, evidence, containment and eradication under change control, verified recovery and a blameless review.
About this course
An analyst decides what an alert means. An incident responder decides what to do once something bad has actually happened — and has to do it without destroying the evidence that explains how it started or breaking the systems that still have to work. This course is the "Incident response" stage of the Defensive Security pathway, and it follows SOC Analyst Foundations (ULC-006). You work on **soc01**, an Ubuntu 24.04 lab machine that carries a **synthetic, inert compromised-host scenario**: a brute force succeeded, and the intruder left planted persistence (a systemd service and timer, a cron entry and an SSH implant key), a tampered administrative script and an inert web-shell file. Everything is generated inside your own lab from documentation-range addresses; the payload never connects anywhere, the SSH key bodies are not usable, and the "web shell" is an inert marker. No production system, SOC, or real host is ever involved. Across ten lessons you practise the lifecycle as it is actually worked, following the current revision of NIST SP 800-61 (Rev. 3, the CSF 2.0 model): triage and declaration with severity and confidence recorded separately; scoping by pivoting across authentication, web, process, socket and telemetry evidence; super-timeline reconstruction in UTC; evidence handling in order of volatility with hashes and a chain of custody; containment, eradication and recovery driven through a written change record with rollback — and graded on real host state: the planted persistence removed and the legitimate services untouched; an incident report whose confidence language matches the evidence; and a blameless post-incident review that turns the case into detection and preparation improvements. The final project hands you a fresh, unlabelled incident and asks you to work it end to end and deliver a declaration, scope, timeline, hashed evidence package, containment and recovery through change control, a report and a review — graded against a rubric and automated lab checks. It leads into Detection Engineering (ULC-111), where the lessons learned here become detections.
- Content time
- 14 h 40 min
- Lessons
- 10
- Lab
- Yes
- provisioned for you
- Certificate
- Yes
- on completion
Lesson 1 is free. Enroll in a career path to access its full courses.
Lesson 1 is a free preview — read it without an account.

Outline
Lessons
Lesson 1: Events, alerts, incidents and the lifecycleFree preview
What separates an alert from an incident, the modern incident-response lifecycle as NIST now describes it, and how to declare an incident with a severity and a confidence recorded separately.
1 h 20 minLesson 2: Preparation — the plan, the playbook and readiness
The preparation that makes a response fast — an incident-response plan, playbooks, a contact tree, an evidence kit and logging readiness — and a tabletop of the case you just declared.
1 h 15 minLesson 3: Scoping and triage
Pivot from the successful login across authentication, web, process, socket and telemetry evidence — and the live host — to a bounded scope statement and a weighted indicator list.
1 h 40 minLesson 4: Super-timeline reconstruction
Merge authentication, web and telemetry sources — which express time three different ways — into one UTC timeline, mark the first malicious action and the persistence, and derive the dwell time.
1 h 30 minLesson 5: Evidence handling and chain of custody
Collect in order of volatility, hash what you keep, and record a chain of custody another responder can verify — building an evidence package with its own manifest before anything on the host is changed.
1 h 30 minLesson 6: Reading persistence for containment
Read each planted persistence artifact for exactly what it does and what removing it changes, then write a containment decision record that maps every artifact to an action, an evidence step and a risk.
1 h 25 minLesson 7: Containment through a change record
Cut the intruder's persistence and return path on the live host — under a written change record with rollback, evidence captured first — while leaving nginx and the legitimate services untouched.
1 h 40 minLesson 8: Eradication and recovery
Remove the payload and the web shell, recover the tampered binary from a verified known-good copy, and build a reusable verification script that proves a bundle is clean against a known-good baseline.
1 h 35 minLesson 9: The incident report
Write the report that survives the incident — eight sections, observation separated from inference, a confidence word on every claim, and notification concepts explained without giving legal advice.
1 h 30 minLesson 10: Lessons learned and improvement
Run a blameless post-incident review, compute the response intervals honestly, turn the case into a detection and a preparation improvement, and seal the case package.
1 h 15 min
Hands-on
Your lab
Real virtual machines on the Ultiblob cluster, reached from your browser. You administer them; we provision and destroy them.
- vm-01soc01linux
Provisioned for you when you launch the lab from the course. The machines are yours for the access window; release them and launch again whenever you like.
Where it leads