inflearn logo

Incident Analysis: Finding the Core Issue

This is a practice-oriented course that provides the basic knowledge required to perform duties as a security analyst and conducts incident analysis training through hands-on exercises. We will explore incident analysis methods from a practical perspective necessary for corporate intrusion response and analysis tasks.

(4.7) 60 reviews

545 learners

Level Basic

Course period Unlimited

Forensic
Forensic
security
security
web-security
web-security
security training
security training
cybersecurity
cybersecurity
Forensic
Forensic
security
security
web-security
web-security
security training
security training
cybersecurity
cybersecurity

Reviews from Early Learners

4.7

5.0

조세근

31% enrolled

This is a helpful lecture.

5.0

김채원

100% enrolled

Wow, this is the best. I now have a clear understanding of the parts I was unsure about before. Thank you.

5.0

seongin-joo

31% enrolled

Concise and important lecture content

What you will gain after the course

  • You will learn how to analyze the causes of security incidents.

  • You will learn about security solutions for responding to cybersecurity threats.

  • You can practice the incident response analysis process.

Recommended for
these people

Who is this course right for?

  • SOC Security Analyst

  • Corporate IT Security Practitioner

  • Incident Response Team (Blue Team)

  • Security monitoring personnel

  • Security Consultant

  • Other Incident Response Analysis Practitioners

Need to know before starting?

  • Basic understanding of cybersecurity

  • Understanding IDS and web application configuration, and web server response codes

Hello
This is BIGROOT SECURITY

545

Learners

60

Reviews

4.7

Rating

1

Course

I performed security incident analysis and response for private companies and public institutions as a member of the AhnLab CERT team. During the March 20 DarkSeoul campaign, I conducted system inspections for domestic broadcasting stations, and I also supported the investigation of compromised systems during the Nate personal information leak incident. I have carried out numerous digital forensic investigations into various security breaches targeting both private and public sector organizations.

At IBM Korea, I served as a PM for SOC implementation and operations projects, where I was responsible for designing security infrastructure and developing deployment and operational processes.

As a technical security solution specialist at Cisco Korea, I diagnosed customer environments and provided strategic advice on improvements, leveraging my expertise in security architecture design and threat response scenarios.

I am currently working as a solution engineer at a foreign security firm.

• Security Consultant: Designed, built, and operated security enhancement strategies through security infrastructure consulting • Security Operations Center (SOC) Consulting: Performed SOC establishment consulting and operational tasks

• Security Consultant: Designed, implemented, and operated security enhancement strategies through security infrastructure consulting

• Security Operations Center (SOC) Consulting: Performed SOC establishment consulting and operational tasks

• Security Service Product Development: Development of next-generation security monitoring solutions & services

• Incident Response: Numerous cases across military, public, and private sectors

Consulting: Performed SOC establishment consulting and operations • Security Service Product Development: Developed next-generation security monitoring solutions & services • Incident Response: Numerous cases across military, public, and private sectors

Consulting: Performed SOC establishment consulting and operations • Security Service Product Development: Developed next-generation security monitoring solutions & services • Incident Response: Numerous cases across military, public, and private sectors

More

Curriculum

All

74 lectures ∙ (7hr 48min)

Course Materials:

Lecture resources
Published: 
Last updated: 

Reviews

All

60 reviews

4.7

60 reviews

  • seonginjoo7350님의 프로필 이미지
    seonginjoo7350

    Reviews 1

    Average Rating 5.0

    5

    31% enrolled

    Concise and important lecture content

    • cw070393님의 프로필 이미지
      cw070393

      Reviews 3

      Average Rating 5.0

      5

      100% enrolled

      Wow, this is the best. I now have a clear understanding of the parts I was unsure about before. Thank you.

      • cskone1373님의 프로필 이미지
        cskone1373

        Reviews 6

        Average Rating 5.0

        5

        31% enrolled

        This is a helpful lecture.

        • seungwonlee4840님의 프로필 이미지
          seungwonlee4840

          Reviews 2

          Average Rating 2.0

          1

          100% enrolled

          It's neither beginner nor intermediate, it's ambiguous. Honestly, I don't think it's a course worth recommending.

          • hyeokjang1567님의 프로필 이미지
            hyeokjang1567

            Reviews 4

            Average Rating 3.3

            1

            33% enrolled

            It's such a shame. I wanted to study the infringement accident practice rather than the introductory talk that can be easily found on YouTube, but in the actual practice, there is no explanation at all, and you proceed alone and only talk about the conclusion. Also, from the middle, strange background music suddenly keeps playing... I can't hear the explanation at all. The practice video seems to be quite old based on the file modification date and such.

            • bigrootsecurity
              Instructor

              Hello, this is Song Dae-geun. Thank you for sharing your course review. The three practical contents included in the lecture are designed to maximize the practical skills of the learner by performing analysis directly as a breach incident analyst and achieving the practical objectives (e.g., identifying the attacker IP, etc.). The learning objective of the practical contents is to analyze the practical textbook directly, derive answers to the questions in the practical objectives, and review the analysis results by comparing them with the actual breach incident analysis results in the next chapter (practical review) and confirm the answers to the questions in the practical objectives. However, if you had any difficulties with the practical or have any questions while analyzing the three practical textbooks, please register in “Ask a Question”. We will answer your questions after checking the related content. If you let us know of any videos among the three practical review videos where the lecture explanation cannot be heard due to audio, we will update them by correcting the balance of the background music. The files related to the practical were selected as practical textbooks based on representative attack cases (e.g., the 3.20 Internet crisis) at the time when the actual incident occurred. Reference - https://namu.wiki/w/3.20%20%EC%A0%84%EC%82%B0%EB%A7%9D%20%EB%A7%88%EB%B9%84%EC%82%AC%ED%83%9C Thank you for taking the class until the end of the hot summer.

          Similar courses

          Explore other courses in the same field!

          25% off for new members

          $49.40

          25%

          $59.40