Group Purchasing
Group Purchasing

What Is the GLIR Certification?

The GIAC Linux Incident Responder (GLIR) certification validates a practitioner’s knowledge of Linux incident response and threat hunting. Certification holders are qualified to conduct system triage, perform evidence collection, and analyze incidents to identify an attack’s initial entry point and its movement across Linux systems.

By the numbers

3 hrs

Exam duration

82

Questions

66%

Min. passing score

What GLIR Covers

GIAC publishes 13 exam objectives for GLIR, which group into five practical domains.

Linux Foundations and Artifacts

Linux OS Fundamentals, Linux OS File System Structure, and Linux File System Artifacts: command line basics, file system layout, persistence mechanisms, and the password file structure.

Disk Evidence and File Systems

Linux File System Fundamentals and Analysis and Evidence Collection and Mounting: file system analysis with The Sleuth Kit, plus physical, virtual, and volatile evidence collection.

Log and Event Analysis

Linux OS Event Log Introduction, Analyzing Linux Events, and Analyzing Linux Application Events: system, authentication, audit, and journal logs, plus webserver, database, file sharing, and host firewall logs.

Triage, Memory, and Timelines

Incident Response Triage, Linux Memory and Device Profiling Analysis, and Linux Timeline Analysis: triage workflows and collection scripts, live memory analysis, and timeline concepts specific to Linux.

Hunting and Anti-Forensics

Linux Threat Hunting and Incident Response and Analyzing Anti-Forensics Techniques: threat intelligence, hunting, playbooks and response workflows, recovering deleted files, and detecting timestamp manipulation.

Prepare With This Course

FOR577: LINUX Incident Response and Threat Hunting

How FOR577 Prepares You for GLIR

FOR577 is built around the exam objectives that make up the GLIR certification: 

  • Section 1, Linux Incident Response and Analysis builds skills tested under Linux OS Fundamentals, Linux OS File System Structure, and Linux File System Artifacts.
  • Section 2, Disk Analysis and Evidence Collection aligns with Linux File System Fundamentals and Analysis, Evidence Collection and Mounting, and the threat intelligence and hunting portions of Linux Threat Hunting and Incident Response.
  • Section 3, Linux Logging and Log Analysis builds skills tested under Linux OS Event Log Introduction, Analyzing Linux Events, and Analyzing Linux Application Events.
  • Section 4, Live Response and Volatile Data aligns with Incident Response Triage, Linux Memory and Device Profiling Analysis, and Linux Timeline Analysis.
  • Section 5, Advanced Incident Response Techniques builds skills tested under Analyzing Anti-Forensics Techniques and the playbook and response workflow portions of Linux Threat Hunting and Incident Response.
  • Section 6, The APT Incident Response Challenge applies the full set of skills in a capstone investigation of an advanced persistent threat intrusion into a Linux enterprise environment.

Across all six sections, 29 hands-on labs and a capstone APT Incident Response Challenge give you the chance to apply each skill on realistic Linux intrusion evidence before you sit the exam. 

Read the full GLIR certification overview 

FOR577 Course Author

Tarot (Taz) Wake
Tarot (Taz) Wake

Tarot (Taz) Wake

Managing Director (Information Security) at Halkyn Consulting Ltd

With FOR577, Taz has authored the first course to systematize threat hunting on Linux systems. His operational leadership—from military intelligence to heading a FTSE100 CSIRT—has fortified global cyber defense capabilities across sectors.

Read more about Tarot (Taz) Wake

Who Should Pursue GLIR

Incident Response Team Members

Threat Hunters

SOC Analysts

Experienced Digital Forensic Analysts

Federal Agents and Law Enforcement

Red Team Members, Penetration Testers, and Exploit Developers

Frequently Asked Questions

GLIR validates a practitioner’s knowledge of Linux incident response and threat hunting. Certification holders are qualified to conduct system triage, perform evidence collection, and analyze incidents to identify an attack’s initial entry point and its movement across Linux systems. 

GIAC lists the GLIR exam as one proctored exam with 82 questions, a 3-hour time limit, and a minimum passing score of 66%. GIAC periodically reviews exam specifications, so check the Certification Information section of your GIAC account for the format that applies to your attempt. 

GIAC certifications are renewed on a recurring cycle through continuing education credits and a maintenance fee. For the current renewal requirements, see GIAC’s renewal page. 

GIAC lists GLIR for incident response team members, threat hunters, SOC analysts, experienced digital forensic analysts, federal agents and law enforcement, and red team members, penetration testers, and exploit developers. 

FOR577: LINUX Incident Response and Threat Hunting maps to the GLIR exam objectives across six sections, with 29 hands-on labs and a capstone APT Incident Response Challenge, using the SANS SIFT Workstation. It provides great training if you’re thinking of pursuing GLIR, though SANS training is not required for GIAC certification. See FOR577. 

SANS Institute is a training organization. GIAC LLC is an independent certification body accredited by the ANSI National Accreditation Board (ANAB) under ISO/IEC 17024:2012. Completion of SANS training is not required for GIAC certification, nor does it guarantee a passing exam result.

Ready to earn your GLIR certification?

Add the GLIR exam attempt when you register for FOR577.