Introduction to Incident Response
Summary of the Course
This virtual job simulation provided a hands-on deep dive into the practical work carried out by incident response teams, focusing heavily on technical activities centered around incident reporting, security monitoring, and ethical hacking. Throughout the tasks, I explored the mechanics of parsing incident reports alongside live data analysis and network monitoring. Industry-standard cybersecurity platforms such as Splunk and specialized testing environments like HackThisSite were actively utilized to simulate real-world banking threat defense.
Learning Objectives
The primary focus of this course was split into many different activities and goals to help gain a deeper understanding of Incident Reporting and Monitoring, Those were:
- To gain an understanding of the importance of incident reports and how they contribute to overall security.
- To learn the fundamentals of data monitoring and analysis using Splunk.
- To strengthen my understanding and ability to perform ethical hacking in a safe environment.
- To deepen my knowledge of concepts related to security incidents and risk mitigation.
Work Produced & Problems Overcome
For this task, I assumed the role of a Security Operations Center (SOC) analyst with the goal of turning raw data into clear and informative results and tables. To complete this, I used Splunk. Splunk is an industry-standard platform used by cybersecurity professionals to accurately display important data and statistics in a visually appealing and informative way. Using this tool, I transformed raw retail data in relation to industry fraud. Upon completion of this task, I had built an interactive dashboard inside of Splunk, utilizing its real-time updating and mapping capabilities. This task was instrumental in helping me master the fundamentals of data and traffic monitoring within cybersecurity.
Task 2 was completely centered around ethical hacking. Ethical hacking refers to the act of utilizing methods used by attackers to attempt to bypass and access systems; not only does this test current defenses, but it also highlights potential vulnerabilities present within a system. Crucially, ethical hacking is done with the permission of the business. Using HackThisSite, I completed their introductory challenges on ethical hacking. Provided with a safe environment, I learned about concepts such as SQL Injection and web traffic interception using Burp Suite. Following the completion of the 10 problems, I wrote a comprehensive report outlining how the security of the website could be improved while highlighting the specific attack methods I used to gain access. This task taught me ethical hacking fundamentals alongside introducing me to industry-standard software like Burp Suite and the ability to write informative reports on my findings.
Task 4 saw me assume the role of a Blue Team incident responder within an organization. My mandate was to manage a crisis currently in progress: a live cyberattack was occurring, and as a cybersecurity analyst, it was up to me to contain, eradicate, and report the threat. My first course of action was to outline how I would stabilize the systems using incident response playbooks and strong protocols to describe my containment strategy. I continued my report by discussing the precise methods and precautions required to ensure the threat was completely eradicated from the system, before outlining future preventative measures to stop an incident like this from happening again. Finally, I created an educational infographic using Canva to highlight the dangers of cyberattacks and outline mitigation steps specifically centered around password security. This task served as my first practical introduction to managing an active breach, utilizing both identification and mitigation tactics, while the infographic allowed me to translate technical concepts into security awareness material.
Tools Used
To complete this course it involved both hacking software and reporting tools to comprehensively cover an active incident. The tools I used:
Learning Outcomes
Throughout this course, I developed a strong understanding of the work done by incident responders and ethical hackers. This course was split into two core focuses, Incident Response and Ethical Hacking, and the concepts taught in both deepened my knowledge immensely. Gaining hands-on experience with industry-standard tools and getting comfortable with methods to access data was instrumental for me. The active security incident not only tested my ability to work under pressure but also required me to adapt and work through the crisis section by section. Being required to think short-term and long-term, and provide mitigation advice gave me exceptional insight into the steps taken to handle an attack and the interconnectedness of cybersecurity. Overall, this course not only introduced me to ethical hacking but also improved my ability to write technical reports and critically evaluate each stage; finally, creating the infographic enhanced my creative and design skills using Canva.