The Exam
INE Security’s eCIR is the only certification for Incident Responders that evaluates your ability to use cutting-edge Incident Response techniques, inside a fully featured and real-world environment.
The candidate will receive a real-world engagement within INE’s Virtual Lab environment. You will need an Internet connection and VPN software in order to carry out this exam.
Knowledge Domains
By obtaining the eCIR, your skills in the following areas will be assessed and certified:
- Network packet/traffic analysis
- Tools such as Wireshark, ELK & Splunk
- Actionable SIEM searches
- Event & log correlation
- Event analysis
- Process analysis and anomaly detection
- Understanding and detecting any stage of the “Cyber Kill Chain” (Information Gathering, Scanning, Exploitation, Post-exploitation)
Prerequisites
The eCIR is a highly technical certification that requires advanced knowledge of networks, systems and cyber attacks. Anyone can attempt the certification exam; however, below are suggested skills to possess for a successful outcome:
- Letters of engagement and the basics related to an Incident Response engagement
- Advanced networking concepts
- Knowledge of Incident Response processes and methodologies
- Packet/traffic analysis
- Ability to correlate events and logs
- Familiarly with tools such as Wireshark, ELK & Splunk
- Cyber crime Techniques, Tactics & Procedures
- Detection of all stages of the “Cyber Kill Chain”
- Familiarity with ELK and Splunk searches
- Ability to effectively analyze thousands of events within a SIEM
- Good understanding of Windows (and Sysmon) events
- Attacker activity detection through process analysis
Expiration
The current version of the eCIR certification does not have an expiration date.
Certification Process
There are two ways to get certified.
Purchase an INE subscription and take the Incident Handling and Response Professional learning path.
The Incident Handling & Response Professional learning path takes you from a basic-intermediate understanding of Incident Response activities to a Professional level. You will receive valuable theory courses and a number of hands-on practical sessions within INE’s Virtual Labs.
OR
Attempt the certification without training
INE allows anybody to attempt the certification exam without attending any training. Candidates should do so at their own risk. The candidate that feels prepared enough to demonstrate their practical and professional skills can purchase an eCIR voucher and go through the certification process.