All Modules INCIDENT RESPONSE

Incident Response · Complete Guide

Eight chapters covering the full incident response lifecycle from NIST 800-61 and SANS PICERL through preparation, scoping and evidence, containment strategy, eradication, recovery, post-incident review, and specialized playbooks for ransomware, BEC, insider threat, and cloud incidents. Built for analysts moving from SOC-scoped triage into full ownership of an incident from detection to closure.

8 CHAPTERS
~12 HRS CONTENT
BEGINNER to ADVANCED SKILL RANGE
SEP 2026 LAST UPDATED
MODULE PROGRESS 0 / 8 chapters complete
NIST 800-61 PICERL containment eradication recovery ransomware BEC cloud IR

ALL CHAPTERS

/
01
BEGINNER 25 min

Incident Response Foundations: NIST, PICERL & Team Roles

SOC-scoped incident handling versus full IR ownership, the NIST 800-61 and SANS PICERL frameworks compared, incident classification and severity, and the roles that make up an IR team.

PICERL NIST 800-61 IR team roles
02
BEGINNER 30 min

Preparation: IR Plans, Playbooks & Tabletop Exercises

Building an incident response plan, the difference between an IRP and a playbook, IR tooling and the jump bag, and running tabletop exercises.

IR plan playbooks tabletop exercises
03
INTERMEDIATE 35 min

Detection and Analysis: Scoping, Evidence & Timelines

Scoping an incident once it becomes full IR, evidence collection and chain of custody, building an incident timeline, and common analysis pitfalls.

scoping chain of custody timeline reconstruction
04
INTERMEDIATE 35 min

Containment Strategy: Isolation Decisions Under Pressure

Short-term versus long-term containment, the factors that drive containment decisions, containment techniques by incident type, and the contain-versus-watch dilemma.

containment network isolation business impact
05
INTERMEDIATE 30 min

Eradication: Removing the Threat for Good

Root cause versus symptom removal, common eradication actions, verifying eradication actually worked, and deciding when to rebuild instead of clean.

eradication root cause credential rotation
06
INTERMEDIATE 30 min

Recovery: Restoring Trust in Compromised Systems

Phased restoration priorities, validation before returning systems to production, heightened post-recovery monitoring, and communicating recovery status.

recovery phased restoration validation
07
ADVANCED 35 min

Post-Incident Activity: Lessons Learned, Metrics & Disclosure

Running a blameless lessons-learned meeting, writing an after-action report, the IR metrics that matter, and legal and regulatory breach notification obligations.

lessons learned after-action report breach notification
08
ADVANCED 40 min

Specialized IR Scenarios: Ransomware, BEC, Insider Threat & Cloud

How incident response adapts for ransomware, business email compromise, insider threats, and cloud environments, tying the full PICERL lifecycle together.

ransomware BEC cloud IR

PREREQUISITES & OUTCOMES

WHAT YOU SHOULD KNOW

  • No prior IR experience required, Chapter 1 builds the frameworks and terminology from scratch
  • SOC Operations is a good companion module, since this module deliberately picks up where SOC-scoped incident handling ends
  • General awareness of common attack types (malware, phishing, unauthorized access) is useful but not assumed
  • No coding or forensic-tool experience required, this module covers process and decision-making, not tool operation

WHAT YOU WILL KNOW AFTER

  • How NIST 800-61 and SANS PICERL structure the incident response lifecycle, and how the two map to each other
  • How to build an IR plan and playbooks, and run a tabletop exercise to test them
  • How to scope an incident, collect evidence with proper chain of custody, and reconstruct a timeline
  • How to choose between short-term and long-term containment, and match technique to incident type
  • The difference between symptom removal and true eradication, and when to rebuild instead of clean
  • How to validate and phase a recovery, and keep monitoring after systems return to production
  • How to run a blameless lessons-learned process, read IR metrics, and navigate disclosure obligations
  • How the full lifecycle adapts for ransomware, BEC, insider threat, and cloud-native incidents

RECOMMENDED TOOLS

H3AD-SEC tools that pair directly with this module's content.