IMT3004

Incident Response, Ethical Hacking and Forensics

Last taught 2021

Autumn

Gjøvik

English

Overview

77 candidates

Average grade

B

3.92

0.41

Pass rate

100%

2 points

Grade distribution
Average over time
Pass rate over time

About this course

Content

I. Incedent response
- Incident response planning: preparation, organization, building and
running a CSIRT, operational issues, hiring and training of personnel
- Incident response management: prevention, detection, notification,reaction, recovery, maintenance
- Advanced computer network defence: vulnerability and threat
assessment, threat intelligence and situational awareness, tools and
processes, information sharing

II. Ethical Hacking
- Ethical hacking methodology and process: Reconnaissance, scanning, exploitation and post-exploitation
- Low level vulnerability: buffer overflow, heartbleed, shellshock, EthernalBlue, ...etc
- Web exploitation: cross site scripting, SQL injection, cross site request forgery
- Password security: brute force and dictionary attacks, rainbow tables, and mitigations

III. Forensics
- Digital forensics methodology
- Live and file system forensics
- Forensic reconstructions
- Internet and network forensics

Learning outcomes

Knowledge:
The candidate has knowledge about different activities associated with securing, attacking and investigating computer systems, including
- The candidate has general knowledge of planning for incident response
and managing the operational aspects of the incident response team.
- The candidate has general knowledge of how to perform incident
response for various types of adverse incidents, including intrusions
from advanced threat actors
- The candidate has general knowledge of digital Forensics methodology with a solid understanding of requirements for handling digital evidence.
- The candidate has general knowledge if ethical hacking techniques that are used to understand how attacker think and operate and identify weaknesses during operations.


Skills:
The candidate can
- Prepare for incident handling and perform incident response, as well as build, organize and manage an incident response team
- Perform ethical hacking activities to identify vulnerabilities in systems at different levels, exploit these vulnerabilities to gain access, and maintain this access
- Forensic acquisition of digital evidence from computer and network media


General Competence:
Candidates have insight into the methods of planning for incidents, defending information systems and testing these systems for weakness. In case of an incident they are able to collect evidence based on digital forensics methodologies and the relationship with incident handling.

Teaching methods

-Lectures
-Laboratory work
-Exercises
-Project work