
CISA is proud to offer the Initial Triage and Data Collection Cyber Range Training (IR215). We are excited to share this information with stakeholders across the federal enterprise and nationally.
This 4-hour skills development cyber range training provides best practices for strengthening detection and initial response capabilities for more effective triaging. Through case studies, presentations by expert facilitators, demonstrations, and lab exercises, participants will explore the tools and techniques necessary to identify suspicious and malicious activity in an enterprise environment.
Throughout the course participants will:
- Practice initial response tactics to an Advanced Persistent Threat (APT) including ransomware attacks, while emphasizing the importance of speed and accuracy in collecting the data from logs, systems, and network traffic.
- Utilize automated tools for initial data gathering and the manual collection of evidence.
This course is ideal for those working in cybersecurity roles who are interested in learning technical incident response skills and requires active engagement from all participants. The course assumes a mixed audience (e.g., from disparate teams and organizations) of mixed capability.