CNIT 152: Incident ResponseFall 2026 Sam Bowne73883 Thu 6:00 - 9:00 pm
|
Class AttendanceI recommend attending class in-person, but you can also attend class remotely via Twitch.
|
Free Textbook Access
|
TextbookApplied Incident Response, First Edition by by Steve Anson | |||||||||||||||||||||||||||||||
Catalog DescriptionWhen computer networks are breached, incident response (IR) is required to assess the damage, eject the attackers, and improve security measures so they cannot return. This class covers the IR tools and techniques required to defend modern corporate networks. This class is part of the Advanced Cybersecurity Certificate. QuizzesThe quizzes are multiple-choice, online, and open-book. However, you may not ask other people to help you during the quizzes. You will need to study the textbook chapter before the lecture covering it, and take the quiz before that class. Each quiz is due 30 min. before class. Each quiz has 5 questions, you have ten minutes to take it, and you can make two attempts. If you take the quiz twice, the higher score counts. Discussion BoardEach CCSF student must contribute to the Discussion Board in Canvas. There are dates listed in the schedule with Discussion assignment due. GradingGrades are determined from your total points, as shown below. MessagesFor questions, please send a message inside Canvas. | |||||||||||||||||||||||||||||||
Schedule | ||||
|---|---|---|---|---|
| Thu 8-20 | 1 The Threat Landscape Demo: IR 410: FortiGate 7.6 Operator | |||
| Thu 8-27 | Quizzes: Ch 1 & Ch 2 * IR 410 Flags 1-2 due Discussion 1 * |
2 Incident Readiness Demo: IR 410: FortiGate 7.6 Operator | ||
| Thu 9-3 | Quiz: Ch 3
IR 410 Flags 3-5 due Discussion 2 |
3 Remote Triage Demo: IR 100 and IR 371 | ||
| Thu 9-10 | Quiz: Ch 4-5
IR 100 due Discussion 3 |
4 Remote Triage Tools 5 Acquiring Memory Demo: IR 372, 373, 374 | ||
| Thu 9-17 | Quiz: Ch 6
IR 371 due Discussion 4 |
Demos: IR 350 and IR 400 | ||
| Thu 9-24 | Quiz: Ch 7
IR 372 due Discussion 5 |
6. Disk Imaging Demo: BoTS | ||
| Thu 10-1 | Quiz: Ch 8
IR 350 due Discussion 6 |
7. Network Security Monitoring Demo: BoTS | ||
| Thu 10-8 | No Quiz | TBA | ||
| Thu 10-15 | Quiz: Ch 8
IR 400 due Discussion 7 | 8. Event Log Analysis Demo: BoTS | ||
| Thu 10-22 | Quiz: Ch 9
BoTS Flags 1.1-1.3 due Discussion 8 | 9. Memory Analysis Demo: IR 373 | ||
| Thu 10-29 | Quiz: Ch 10
BoTS Flags 1.4-1.5 due Discussion 9 | 10. Malware Analysis | ||
| Thu 11-5 | TBA | |||
| Thu 11-12 | Quiz: Ch 11
BoTS Flags 2.1-2.2 due Discussion 9 |
11. Disk Forensics Demos: IR 312, IR 301 | ||
| Thu 11-19 | Quiz: Ch 12
BoTS Flags 2.3-2.4 due Discussion 10 |
12. Lateral Movement Analysis Demo: IR 330, IR 303 | ||
| Thu 11-26 | Holiday: No Class | |||
| Thu 12-3 | TBA | |||
| Thu 12-10 | No Quiz
All Extra Credit Due |
Last Class: No new material | ||
| Tue 12-15 through Tue 12-22 | Final Exam available online throughout the week. You can only take it once. | |||
| All quizzes due 30 min. before class | ||||
Lectures | |
|---|---|
Grading Policy (pdf) Syllabus (pdf)
1. The Threat Landscape
Keynote ·
PDF
| |