Simple play icon Course

Incident Response: Network Analysis

by Brandon DeVault

Walking into an incident response situation can be intimidating. This course will teach you how to analyze the network data, correlate network artifacts, and begin to piece together the story of what happened.

What you'll learn

In an incident response scenario, gathering artifacts for analysis can be stressful. In this course, Incident Response: Network Analysis, you'll learn how to analyze network artifacts in a compromised environment. First, you'll take the initial indicators from an attack and pull out relevant artifacts. Next, you'll correlate these artifacts with other phases of the attack chain, working backwards to tell the story of what happened. Finally, you'll broaden your search to look for additional lanes of compromise and determine the incident's full scope. When you're finished with this course, you'll have the skills necessary to operate as an incident response network analyst and understand how to synchronize with the other phases of incident response.

About the author

Brandon DeVault is an Sr. Security Author focusing on general blue team operations, incident response, and threat hunting at Pluralsight. He is also a member of the Florida Air National Guard and works as a threat hunter on a Mission Defense Team (MDT) defending North America’s air tracks. Prior to joining Pluralsight, Brandon worked with Elastic as an Education Architect creating and delivering security content. He also worked with Special Operations Command where he had two deployments to Af... more

Ready to upskill? Get started