Skip to main content
The Cyber Security: ethical hacking and cyber security training, Canada
Core

Linux Incident Response and Threat Hunting

Linux incident response gets far less attention than Windows, yet Linux runs the servers, containers and cloud workloads attackers most want. This course covers the artifacts, timelines and techniques that matter on those systems.

You triage production hosts without taking services down, analyse memory and persistence, investigate container and Kubernetes activity, and hunt across a fleet using tooling that is already installed.

Duration
8 weeks
Format
Live online, instructor-led
Prerequisites
Digital Evidence Acquisition and Rapid Triage
Class size
Capped at 12 learners
Linux Incident Response and Threat Hunting

What you will be able to do

  • Triage a live Linux server without interrupting the service it runs
  • Interpret auth logs, wtmp, btmp and systemd journal evidence correctly
  • Find persistence in cron, systemd units, kernel modules and web applications
  • Acquire and analyse Linux memory including in-memory only processes
  • Investigate Docker and Kubernetes activity where the workload no longer exists
  • Build a timeline from Linux file system and log artifacts
  • Detect log tampering, history clearing and other anti-forensic behaviour
  • Hunt across a Linux fleet using standard tooling rather than an agent

Course outline

6 modules

  • Distributions, init systems and where they differ
  • File systems: ext4, XFS and Btrfs
  • Timestamps, inodes and journal evidence
  • Live triage on a production server
  • Collecting evidence without taking the service down

What you need before you start

  • Comfortable working in a Linux shell day to day
  • Basic understanding of processes, permissions and networking on Linux
  • A machine able to run several Linux virtual machines
  • Evidence handling experience or the acquisition course

Who this course is for

  • Responders whose estates run mostly on Linux
  • Platform, DevOps and site reliability engineers pulled into incidents
  • Cloud security staff investigating compromised workloads
  • Forensic analysts extending beyond Windows casework
  • Threat hunters covering Linux servers and containers

Questions about this course

Ready to launch your cyber security career?

Join the next live online cohort. No experience required, just bring the curiosity.