Level 3 — Incident Response & Digital Forensics
Certification-Aligned Stack: CHFI-aligned stack
- 4. First Responder (Included): First response basics, roles of first responder, data acquisition and duplication, evidence preservation
- 5. Encryption (Included): Decrypting seized data using technical means
- 6. Mobile Forensics (Included): Mobile operating systems, investigation precautions, mobile forensics processes
Skill Level: Beginner
Placement Test Required: No
Cybersecurity Pathway: 1
Cybersecurity Pathway Level: 3
Micro-Credential Code: MC10
Certification-Aligned Stack: CHFI
Pathway Recommendation Order: 10
Level 3 — Incident Response & Digital Forensics
Certification-Aligned Stack: CHFI-aligned stack
- 1. Forensic Science — 15%: Computer forensics objectives, cyber crime types (web, email, network, mobile), investigation methodology, expert witness role
- 2. Regulations, Policies and Ethics — 10%: Searching and seizing computers with/without warrant, laws against email crimes, log management laws, mobile forensics laws, BYOD policies, ethics while testifying
- 3. Procedures and Methodology — 20%: Investigating computer crime, computer forensics investigation methodology, digital evidence examination process, chain of custody
Skill Level: Beginner
Placement Test Required: No
Cybersecurity Pathway: 1
Cybersecurity Pathway Level: 3
Micro-Credential Code: MC9
Certification-Aligned Stack: CHFI
Pathway Recommendation Order: 9
Level 3 — Incident Response & Digital Forensics
Certification-Aligned Stack: ECIH-aligned stack
- Module 08: Handling and Responding to Cloud Security Incidents: Cloud-specific incidents, misconfigurations, account compromise
- Module 09: Handling and Responding to Insider Threats: Insider threat detection, investigation, and mitigation
Skill Level: Beginner
Placement Test Required: No
Cybersecurity Pathway: 1
Cybersecurity Pathway Level: 3
Micro-Credential Code: MC8
Certification-Aligned Stack: ECIH
Pathway Recommendation Order: 8
Level 3 — Incident Response & Digital Forensics
Certification-Aligned Stack: ECIH-aligned stack
- Module 04: Handling and Responding to Malware Incidents: Malware classification, analysis, containment and eradication
- Module 05: Handling and Responding to Email Security Incidents: Phishing, spoofing, business email compromise (BEC)
- Module 06: Handling and Responding to Network Security Incidents: Network attacks, DDoS, unauthorized access
- Module 07: Handling and Responding to Web Application Security Incidents: Web attacks, data breaches, API incidents
Skill Level: Beginner
Placement Test Required: No
Cybersecurity Pathway: 1
Cybersecurity Pathway Level: 3
Micro-Credential Code: MC7
Certification-Aligned Stack: ECIH
Pathway Recommendation Order: 7
Level 3 — Incident Response & Digital Forensics
Certification-Aligned Stack: ECIH-aligned stack
- Module 01: Introduction to Incident Handling and Response: IR fundamentals, terminologies, roles and responsibilities
- Module 02: Incident Handling and Response Process: Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned (PICERL model)
- Module 03: Forensic Readiness and First Response: Preparing for investigations, first response procedures, evidence collection
Skill Level: Beginner
Placement Test Required: No
Cybersecurity Pathway: 1
Cybersecurity Pathway Level: 3
Micro-Credential Code: MC6
Certification-Aligned Stack: ECIH
Pathway Recommendation Order: 6