Incident
Response
—
Technical
Skills
1.
Core
Technical
Skills
The
inventory
below
is
grouped
by
functional
domain
.
Each
entry
names
the
skill
and
the
tools
,
techniques
,
or
artefacts
it
covers
.
1.1
Detection
,
Monitoring
&
Alert
Triage
1.2
Host
&
Endpoint
Forensics
SIEM
query
authoring
—
Splunk
SPL
,
Microsoft
Sentinel
KQL
,
Elastic
KQL
/
EQL
,
Google
SecOps
YARA
-
L
EDR
telemetry
investigation
—
CrowdStrike
Falcon
,
Microsoft
Defender
XDR
,
SentinelOne
,
Cortex
XDR
,
Carbon
Black
Detection
engineering
—
Sigma
rules
,
correlation
and
threshold
logic
,
detection
-
as
-
code
,
false
-
positive
tuning
Network
security
monitoring
—
Zeek
,
Suricata
,
Snort
,
NetFlow
/
IPFIX
,
DNS
and
secure
web
gateway
logs
Alert
triage
&
prioritisation
—
severity
classification
,
true
/
false
positive
determination
,
blast
-
radius
scoping
,
escalation
criteria
Log
source
onboarding
—
parsing
,
field
normalisation
,
UTC
timestamp
handling
,
data
-
quality
validation
Cloud
-
native
detection
—
AWS
GuardDuty
and
CloudTrail
,
Azure
Defender
and
Activity
Logs
,
GCP
Security
Command
Center
,
Kubernetes
audit
logs
Evidence
capture
at
triage
—
volatile
data
snapshot
,
process
and
connection
listing
,
screenshot
and
hash
documentation
Live
response
—
order
of
volatility
,
memory
,
process
,
network
and
session
state
collection
Memory
acquisition
&
analysis
—
WinPmem
,
DumpIt
,
Magnet
RAM
Capture
,
LiME
,
AVML
;
Volatility
3,
Rekall
Disk
acquisition
&
preservation
—
write
blockers
,
FTK
Imager
,
Guymager
,
dd
/
dcfldd
;
E
01,
AFF
4,
raw
;
MD
5/
SHA
-256
verification
Windows
artefact
analysis
—
$MFT
and
$UsnJrnl
,
Prefetch
,
Amcache
,
ShimCache
,
SRUM
,
LNK
/
Jump
Lists
,
Shellbags
,
USB
history
Registry
forensics
—
SYSTEM
,
SAM
,
SECURITY
,
NTUSER
.
DAT
,
UserAssist
,
Run
keys
,
services
and
scheduled
-
task
persistence
Timeline
analysis
—
Plaso
/
log
2
timeline
,
Timesketch
,
KAPE
,
Velociraptor
VQL
,
Eric
Zimmerman
utilities
macOS
&
Linux
forensics
—
Unified
Logs
,
FSEvents
,
launchd
,
journald
,
BSM
audit
,
shell
history
,
ELF
artefacts
Anti
-
forensics
detection
—
timestomping
,
log
deletion
,
secure
wipe
artefacts
,
rootkit
and
hidden
-
object
discovery
1 / 5
1.3
Network
Forensics
&
Traffic
Analysis
1.4
Malware
Analysis
&
Reverse
Engineering
1.5
Threat
Hunting
&
Threat
Intelligence
1.6
Cloud
,
Identity
&
Container
Incident
Response
Packet
capture
&
analysis
—
Wireshark
/
tshark
,
tcpdump
,
Arkime
,
NetworkMiner
,
PCAP
carving
and
file
extraction
Protocol
-
level
investigation
—
HTTP
(
S
),
SMB
,
RDP
,
Kerberos
,
LDAP
,
DNS
tunnelling
,
TLS
SNI
inspection
C
2
and
beacon
detection
—
interval
and
jitter
analysis
,
DGA
identification
,
domain
and
IP
reputation
pivoting
Exfiltration
scoping
—
volume
and
timing
baselines
,
anomalous
egress
destinations
,
encrypted
channel
analysis
TLS
inspection
—
SSLKEYLOGFILE
decryption
,
certificate
review
,
JA
3/
JA
3
S
and
JA
4
fingerprinting
Lateral
movement
mapping
—
Nmap
,
masscan
,
flow
-
record
analysis
,
SMB
and
RDP
session
reconstruction
Static
analysis
—
PE
/
ELF
/
Mach
-
O
structure
,
imports
and
exports
,
strings
,
entropy
,
packer
and
compiler
detection
Dynamic
analysis
—
CAPE
,
Cuckoo
,
Joe
Sandbox
,
Any
.
Run
,
Procmon
/
ProcExp
,
API
Monitor
,
Fakenet
-
NG
,
INetSim
Disassembly
&
debugging
—
Ghidra
,
IDA
,
x
64
dbg
,
WinDbg
,
dnSpy
,
radare
2/
rizin
Script
&
document
analysis
—
PowerShell
deobfuscation
and
Script
Block
4104
review
,
oletools
/
oledump
,
VBA
macro
extraction
,
JavaScript
deobfuscation
YARA
rule
development
—
signature
authoring
,
retro
-
hunting
across
collected
evidence
sets
Fileless
&
LOLBin
abuse
analysis
—
WMI
,
mshta
,
rundll
32,
regsvr
32,
certutil
execution
chains
Ransomware
triage
—
family
identification
,
encryption
scope
,
ransom
note
and
key
-
material
analysis
,
decryptor
assessment
Hypothesis
-
driven
hunting
—
hunts
mapped
to
MITRE
ATT
&
CK
techniques
and
procedures
IOC
lifecycle
management
—
extraction
,
enrichment
,
scoring
,
expiry
;
STIX
/
TAXII
,
MISP
,
OpenCTI
Adversary
infrastructure
research
—
passive
DNS
,
certificate
transparency
,
Shodan
,
Censys
,
VirusTotal
,
MalwareBazaar
Baseline
&
anomaly
analysis
—
UEBA
,
statistical
outlier
review
,
peer
-
group
deviation
Adversary
emulation
—
Atomic
Red
Team
,
MITRE
Caldera
,
Prelude
Operator
,
purple
-
team
validation
of
detections
Intelligence
reporting
—
campaign
tracking
,
attribution
confidence
,
TTP
-
based
detection
gap
analysis
Cloud
credential
compromise
response
—
access
key
rotation
,
session
revocation
,
role
-
assumption
chain
analysis
Cloud
audit
log
investigation
—
CloudTrail
,
Azure
Activity
and
Entra
ID
sign
-
in
logs
,
GCP
Cloud
Audit
Logs
Identity
attack
response
—
Kerberoasting
,
DCSync
,
Golden
Ticket
,
MFA
fatigue
,
token
and
OAuth
grant
theft
SaaS
incident
response
—
Microsoft
365
Unified
Audit
Log
,
Google
Workspace
admin
audit
,
mailbox
rule
and
forwarding
review
2 / 5
1.7
Automation
,
Scripting
&
Tooling
1.8
Containment
,
Eradication
&
Recovery
1.9
Evidence
Handling
&
Forensic
Soundness
Key
takeaway
:
a
well
-
rounded
responder
needs
depth
in
at
least
two
of
the
four
pillars
—
endpoint
forensics
,
network
forensics
,
malware
analysis
,
and
cloud
/
identity
response
—
plus
working
fluency
in
SIEM
querying
and
scripting
.
Breadth
across
all
nine
domains
at
a
foundational
level
is
the
baseline
;
specialisation
is
what
distinguishes
senior
DFIR
practitioners
.
Container
&
Kubernetes
forensics
—
audit
logs
,
image
layer
inspection
,
admission
control
,
runtime
detection
with
Falco
,
Sysdig
,
Tetragon
Data
exposure
scoping
—
S
3/
Blob
/
Drive
access
review
,
download
and
share
event
analysis
,
DLP
alert
triage
Scripting
—
Python
,
PowerShell
,
Bash
,
Go
fundamentals
,
regular
expressions
Query
languages
—
SPL
,
KQL
,
EQL
,
SQL
,
YARA
-
L
SOAR
playbook
development
—
Palo
Alto
XSOAR
,
Splunk
SOAR
,
Tines
,
Torq
,
Swimlane
Response
automation
—
EDR
containment
APIs
,
identity
provider
APIs
,
ticketing
integration
(
Jira
,
ServiceNow
)
Detection
-
as
-
code
pipelines
—
Git
,
CI
/
CD
for
rules
,
unit
-
tested
detections
,
Terraform
-
built
IR
lab
environments
Endpoint
telemetry
tooling
—
Velociraptor
artefacts
,
osquery
packs
,
Sysinternals
suite
,
custom
collection
scripts
Network
containment
—
host
isolation
,
network
segmentation
,
ACL
and
firewall
blocks
,
DNS
sinkholing
Identity
containment
—
account
disablement
,
credential
and
secret
rotation
,
token
/
session
revocation
,
conditional
access
enforcement
Eradication
—
persistence
removal
,
GPO
and
Active
Directory
remediation
,
patching
,
clean
rebuild
decisions
Recovery
validation
—
monitoring
windows
,
re
-
infection
detection
,
restoration
from
verified
backups
Crisis
coordination
—
bridge
call
management
,
parallel
workstream
tracking
,
stakeholder
and
legal
notification
inputs
Chain
of
custody
—
seizure
,
labelling
,
secure
storage
,
transfer
documentation
Forensic
soundness
—
hashing
,
write
blockers
,
minimal
handling
,
contemporaneous
investigator
notes
Legal
hold
&
privacy
constraints
—
scope
limitation
,
jurisdictional
handling
,
privileged
material
identification
Incident
reporting
—
executive
summary
,
technical
timeline
,
root
-
cause
analysis
,
lessons
-
learned
and
control
recommendations
3 / 5
2.
Tooling
by
Domain
Primary
commercial
platforms
paired
with
the
open
-
source
equivalents
most
teams
keep
available
for
specialised
work
.
TABLE
1 —
TOOLING
MAPPED
TO
RES PONS E
DOMAINS
Domain
Primary
tooling
Open
-
source
&
secondary
SIEM
&
detection
Splunk
Enterprise
Security
,
Microsoft
Sentinel
,
Google
SecOps
,
Elastic
Security
Elastic
Stack
,
Wazuh
,
Sigma
,
Chainsaw
,
Hayabusa
Endpoint
detection
&
response
CrowdStrike
Falcon
,
Microsoft
Defender
XDR
,
SentinelOne
,
Cortex
XDR
Velociraptor
,
osquery
,
Sysmon
,
Sysinternals
Host
forensics
Magnet
AXIOM
,
EnCase
,
FTK
,
Cellebrite
Premium
Autopsy
,
KAPE
,
Plaso
,
Timesketch
,
Eric
Zimmerman
utilities
Memory
forensics
Belkasoft
,
Magnet
RAM
Capture
,
Cellebrite
UFED
Volatility
3,
Rekall
,
LiME
,
AVML
,
WinPmem
,
DumpIt
Network
forensics
Arkime
,
Corelight
,
ExtraHop
Reveal
(
x
),
Darktrace
Wireshark
,
Zeek
,
Suricata
,
NetworkMiner
,
tcpdump
Malware
analysis
Joe
Sandbox
,
VirusTotal
Enterprise
,
VMRay
,
Any
.
Run
CAPE
,
Ghidra
,
x
64
dbg
,
dnSpy
,
oletools
,
YARA
Threat
intelligence
Recorded
Future
,
Mandiant
Advantage
,
Flashpoint
MISP
,
OpenCTI
,
Shodan
,
Censys
,
MalwareBazaar
Automation
&
orchestration
Palo
Alto
XSOAR
,
Splunk
SOAR
,
Swimlane
,
Torq
Tines
,
n
8
n
,
Jupyter
,
custom
Python
tooling
Cloud
&
containers
AWS
Security
Hub
,
Microsoft
Defender
for
Cloud
,
Wiz
,
Sysdig
Secure
Prowler
,
ScoutSuite
,
Falco
,
Tetragon
,
kube
-
bench
3.
Proficiency
Scale
Use
the
levels
below
when
assessing
a
responder
,
writing
a
job
description
,
or
building
a
training
plan
.
4 / 5
TABLE
2 —
S KILL
PROFICIENCY
LEVELS
AND
OBS ERVABLE
EVIDENCE
Level
Capability
Observable
evidence
Foundational
Understands
the
concept
and
follows
an
existing
runbook
with
supervision
.
Triages
alerts
correctly
,
collects
defined
artefacts
,
escalates
within
SLA
.
Intermediate
Runs
the
investigation
independently
and
adapts
the
runbook
to
the
case
.
Scopes
an
intrusion
end
-
to
-
end
,
writes
a
defensible
timeline
,
drives
containment
.
Advanced
Handles
novel
or
high
-
severity
incidents
and
improves
the
process
afterwards
.
Leads
a
major
incident
bridge
,
authors
new
detections
,
performs
tool
-
level
forensic
analysis
.
Expert
Sets
organisational
direction
and
is
the
final
technical
authority
on
the
domain
.
Builds
the
IR
programme
,
reverse
-
engineers
novel
malware
,
gives
expert
-
witness
testimony
.
4.
Frameworks
,
Standards
&
Certifications
4.1
Frameworks
&
standards
4.2
Common
certifications
NIST
SP
800-61
—
incident
handling
lifecycle
:
preparation
;
detection
and
analysis
;
containment
,
eradication
and
recovery
;
post
-
incident
activity
SANS
PICERL
—
Preparation
,
Identification
,
Containment
,
Eradication
,
Recovery
,
Lessons
learned
MITRE
ATT
&
CK
—
technique
mapping
for
detection
coverage
,
hunting
hypotheses
and
gap
analysis
;
D
3
FEND
and
Engage
for
defensive
countermeasures
ISO
/
IEC
27035
and
27037–27043
—
incident
management
and
digital
evidence
handling
,
identification
,
collection
and
analysis
NIST
Cybersecurity
Framework
2.0
and
CIS
Controls
v
8
—
control
baselines
supporting
detection
and
response
maturity
Breach
notification
obligations
—
GDPR
72-
hour
regulator
notification
,
PCI
DSS
incident
reporting
,
sector
-
specific
rules
(
HIPAA
,
DORA
,
NIS
2)
CVSS
and
EPSS
—
severity
scoring
and
exploitation
-
probability
prioritisation
during
active
incidents
NIST
SP
800-86
—
integrating
forensic
techniques
into
incident
response
GIAC
—
GCIH
(
Incident
Handler
),
GCFA
(
Forensic
Analyst
),
GNFA
(
Network
Forensic
Analyst
),
GREM
(
Reverse
Engineering
Malware
),
GCIA
(
Intrusion
Analyst
)
Offensive
Security
—
OSCP
,
OSDA
(
Defending
Against
Adversarial
Attacks
)
ISC
²
and
ISACA
—
CISSP
,
CISM
,
CISA
for
governance
and
programme
leadership
roles
Vendor
credentials
—
Microsoft
SC
-200
and
AZ
-500,
Splunk
Certified
Cybersecurity
Defense
Analyst
,
CrowdStrike
Certified
Falcon
Responder
,
AWS
Security
Specialty
Cloud
-
native
—
CKS
(
Certified
Kubernetes
Security
Specialist
),
CCSP
5 / 5