The EC-Council Certified Incident Handler (ECIH) program focuses on a structured approach for performing the incident handling and response (IH&R) process. The IH&R process includes stages like incident handling and response preparation, incident validation and prioritization, incident escalation and notification, forensic evidence gathering and analysis, incident containment, systems recovery, and incident eradication. This systematic incident handling and response process creates awareness among incident responders in knowing how to respond to various types of security incidents.
About the Computer Forensics Deep Dive Workshops
Dark Web Forensics Deep Dive Workshop
In this workshop you will be given a tour of the dark web and walked through the technical details of how it works. You will get hands on experience conducting dark web investigations. This includes how to identify relevant information and how to investigate it.
The Malware and Memory Forensics Deep Dive Workshop
In this workshop, you will learn details of how malware functions, and how it is categorized. Then you will be shown details of the structure of memory, and how memory works. There is plenty of hands-on memory forensics. You will learn how to analyze memory to find evidence of malware.
The Mobile Forensic Deep Dive Workshop
This workshop will show you how to conduct such investigations. You will learn mobile phone architecture, how to use phone forensics tools and open-source tools. There will be a strong focus on Android phones, including how to use the Android Debugging Bridge to perform forensics.