Core
Linux Incident Response and Threat Hunting
Linux incident response gets far less attention than Windows, yet Linux runs the servers, containers and cloud workloads attackers most want. This course covers the artifacts, timelines and techniques that matter on those systems.
You triage production hosts without taking services down, analyse memory and persistence, investigate container and Kubernetes activity, and hunt across a fleet using tooling that is already installed.
- Duration
- 8 weeks
- Format
- Live online, instructor-led
- Prerequisites
- Digital Evidence Acquisition and Rapid Triage
- Class size
- Capped at 12 learners

What you will be able to do
- Triage a live Linux server without interrupting the service it runs
- Interpret auth logs, wtmp, btmp and systemd journal evidence correctly
- Find persistence in cron, systemd units, kernel modules and web applications
- Acquire and analyse Linux memory including in-memory only processes
- Investigate Docker and Kubernetes activity where the workload no longer exists
- Build a timeline from Linux file system and log artifacts
- Detect log tampering, history clearing and other anti-forensic behaviour
- Hunt across a Linux fleet using standard tooling rather than an agent
Course outline
6 modules
- Distributions, init systems and where they differ
- File systems: ext4, XFS and Btrfs
- Timestamps, inodes and journal evidence
- Live triage on a production server
- Collecting evidence without taking the service down
What you need before you start
- Comfortable working in a Linux shell day to day
- Basic understanding of processes, permissions and networking on Linux
- A machine able to run several Linux virtual machines
- Evidence handling experience or the acquisition course
Who this course is for
- Responders whose estates run mostly on Linux
- Platform, DevOps and site reliability engineers pulled into incidents
- Cloud security staff investigating compromised workloads
- Forensic analysts extending beyond Windows casework
- Threat hunters covering Linux servers and containers
Questions about this course
More in digital forensics and incident response
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



