Group Purchasing
Group Purchasing

What Is the GCIH Certification?

The GCIH certification validates a practitioner's ability to detect, respond to, and resolve computer security incidents. Holders understand common attack techniques, vectors, and tools well enough to defend against and respond to attacks as they occur.

By the numbers

4 hrs

Exam duration

106

Questions

69%

Min. passing score

What GCIH Covers

Noting the 15 published objectives group into five practical domains that map directly to SEC504's course sections.

Incident Response and Investigation

Incident Response and Cyber Investigation, Network and Log Investigations, Malware and AI Assisted Investigations: building and applying a structured process for verifying, scoping, and remediating an incident, including using AI to accelerate log and malware analysis.

Scanning, Mapping, and SMB Security

Scanning and Mapping, SMB Security, Detecting Exploitation and Covert Communications Tools: discovering hosts and services, identifying SMB vulnerabilities, and recognizing tools like Metasploit and netcat when attackers use them.

Password and Cloud Credential Attacks

Understanding Passwords, Attacking Passwords, Securing Credentials and Data in the Cloud: identifying password hashes and weaknesses, then defending against credential attacks in cloud environments.

Web Application Attacks

Exploiting Insecure Web Application References, Web Application Injection Attacks, Web Application API Attacks: finding and defending against injection, forced browsing, and API abuse in web applications.

Post-Exploitation and AI Attacks

Endpoint Attack and Pivoting, Detecting Evasive and Post-Exploitation Techniques, Integrating LLMs with Offensive Operations: recognizing persistence, pivoting, and evasion techniques, including attacks targeting LLM integrations

Prepare With This Course

SEC504: Hacker Tools, Techniques, and Incident Handling

How SEC504 Prepares You for GCIH

SEC504 is built around the exam objectives that make up the GCIH certification:

  • Section 1, Incident Response and Cyber Investigations builds skills tested under Incident Response and Cyber Investigation, Network and Log Investigations, and Malware and AI Assisted Investigations.
  • Section 2, Scanning and Enumeration Attacks aligns with Scanning and Mapping, SMB Security, and Detecting Exploitation and Covert Communications Tools.
  • Section 3, Password Attacks and Exploit Frameworks aligns with Understanding Passwords, Attacking Passwords, and Securing Credentials and Data in the Cloud.
  • Section 4, Web Application Attacks aligns with Exploiting Insecure Web Application References, Web Application Injection Attacks, and Web Application API Attacks.
  • Section 5, Post-Exploitation and AI Attacks aligns with Endpoint Attack and Pivoting, Detecting Evasive and Post-Exploitation Techniques, and Integrating LLMs with Offensive Operations.

Across all six sections, 44 hands-on labs and a capstone Capture the Flag event give you the chance to apply each skill against Windows, Linux, and cloud targets before you sit the exam.

Read the full GCIH certification overview here.

SEC504 Author

Joshua Wright
Joshua Wright

Joshua Wright

Director and Senior Security Analyst at CounterHack

Joshua Wright, Senior Technical Director at Counter Hack Challenges and author of SEC504, has spent over two decades teaching and building tools that help defenders identify and counter real-world cyber threats through practical, hands-on learning.

Read more about Joshua Wright

Who It's For

Incident handlers

Incident response team leads

System administrators

Security practitioners and architects

First responders to security incidents

Frequently Asked Questions

GCIH certification holders can detect, respond to, and resolve computer security incidents, using an understanding of common attack techniques, vectors, and tools to defend against and respond to attacks as they occur.

The GCIH exam is one proctored exam, 106 questions, taken over 4 hours, with a minimum passing score of 69%.

GIAC certifications are renewed on a recurring cycle through continuing education credits and a maintenance fee. For the current renewal requirements, see GIAC's renewal page.

GCIH is designed for incident handlers, incident response team leads, system administrators, security practitioners and architects, and first responders to security incidents.

SEC504: Hacker Tools, Techniques, and Incident Handling is built around GCIH's exam objectives, with 44 hands-on labs and a capstone Capture the Flag exercise run against Windows, Linux, and cloud targets.

Ready to earn your GCIH certification?

Add the GCIH exam attempt when you register for SEC504.

Already trained? Register for the exam directly through GIAC here.