This unit explores techniques for gathering evidence of cybersecurity breaches alongside their detection and response. Techniques for analysing and reporting findings from various sources, such as memory, operating systems, email, and network forensics, will be covered. Emphasis is placed on developing and implementing incident response plans and runbooks to address a wide range of security threats effectively. Security hardening techniques will be applied to enhance the resilience of systems like Windows Server against attacks. Configuration and utilisation of Security Information and Event Management (SIEM) systems will be undertaken to monitor, analyse, and respond to potential security threats. Finally, comprehensive incident reports will be prepared, proposing measures to prevent future incidents and improve the overall security response.
On successful completion of this unit, students will be able to:
This unit is studied as part of the following course(s):