Group Purchasing
Group Purchasing
AI SKILLSMAJOR UPDATES

FOR577: LINUX Incident Response and Threat Hunting

FOR577Digital Forensics and Incident Response, Artificial Intelligence
  • 6 Days (Instructor-Led)
  • 36 Hours (Self-Paced)
Course authored by:
Tarot (Taz) Wake
Tarot (Taz) Wake
FOR577: LINUX Incident Response and Threat Hunting
Course authored by:
Tarot (Taz) Wake
Tarot (Taz) Wake
  • GIAC Linux Incident Responder (GLIR)
  • 36 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Intermediate Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 29 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Learn to identify, analyze, and respond to attacks on Linux platforms, including AI and LLM threats, and use threat hunting to find stealthy attackers who bypass existing controls.

Course Overview

This Linux threat hunting and incident response course equips responders to hunt down, identify, counter, and recover from threats across enterprise networks, from APT nation-state actors to organized crime and hacktivists. Constantly updated, it now adds AI and LLM investigations and prepares you for the GLIR (GIAC Linux Incident Response) certification.

What You’ll Learn

  • Detect and contain various adversaries, performing incident response on Linux systems
  • Identify and track malware beaconing to command and control (C2) channels
  • Investigate breach origins, focusing on beachhead identification and adversary tracking
  • Perform in-depth timeline and super-timeline analysis to track user and attacker activity
  • Detect lateral movement and pivots within the enterprise
  • Monitor and trace data movement as attackers exfiltrate critical data
  • Analyze and investigate compromised LLM and other AI platforms to establish attacker activity

Business Takeaways

  • Learn to perform proactive compromise assessments and threat hunts
  • Enhance your knowledge of Linux and adversary behavior
  • Upgrade threat detection capabilities
  • Develop threat intelligence to track targeted adversaries
  • Understand LLM compromises to uncover stealthy attacks
  • Build readiness to detect and respond to AI and LLM-driven incidents
  • Strengthen detection of rootkits and anti-forensic evasion techniques

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in FOR577: LINUX Incident Response and Threat Hunting.

Section 1Linux Incident Response and Analysis

Section one introduces the fundamentals of incident response with a focus on Linux environments. It covers the SANS six-step methodology, the Unified Kill Chain and attacker behaviors, and a hands-on intrusion scenario, while building the Linux command-line and forensic skills used throughout the course.

Topics covered

  • Incident Response Foundations
  • AI and the Future of DFIR
  • Introduction to Linux and Linux Command Line Basics
  • Attack lifecycles and the Unified Kill Chain
  • Reviewing Linux Attacks and hunting through artifacts

Labs

  • SIFT Workstation orientation
  • Understanding Stark Skunkworks
  • Introduction to Linux commands
  • Initial Attack Assessment
  • Reviewing Operating System Files

Section 2Disk Analysis and Evidence Collection

This section covers system analysis and the foundations of threat hunting. You will collect and analyze disk evidence with The Sleuth Kit across the ext4, XFS, and Btrfs file systems, examine Linux package data and executables, and see how cyber threat intelligence supports hypothesis- and intelligence-led hunting.

Topics covered

  • The Sleuth Kit
  • Linux File Systems
  • Disk Evidence Collection and Mounting
  • Linux Package Managers
  • Examining Linux Executables

Labs

  • Introduction to the Sleuth Kit
  • Reviewing filesystem data
  • Disk evidence collection and Mounting
  • Package Management Review
  • Consuming Threat Intelligence

Section 3LINUX Logging and Log Analysis

This section covers Linux log analysis for incident response. It begins with device profiling and logging fundamentals, then covers syslog, the systemd journal, authentication, and Auditd logs. It also covers application logs from web servers, databases, file-sharing services, and firewalls, where evidence of attacks is often found.

Topics covered

  • Device Profiling
  • The Operating System Journal
  • Linux Logging
  • AuditD
  • Application logs, including webservers, databases, filesharing, and firewalls

Labs

  • System and log profiling
  • Investigating the systemd journal
  • Analyzing authentication logs
  • Analyzing audit logs with Auditd and Elasticsearch
  • Reviewing web server, database, and firewall logs

Section 4Live Response and Volatile Data

This section covers investigation of AI and large language model (LLM) systems across local and hybrid deployments, including AI coding assistants and self-hosted platforms. It addresses LLM-specific issues such as prompt injection, data exfiltration, and supply chain attacks, and closes with Linux anti-forensics and guidance on improving incident response.

Topics covered

  • Triage and rapid collection
  • Enterprise response tools (EDR, Sysmon, Kunai, Velociraptor, GRR)
  • Timeline analysis
  • Linux memory acquisition and analysis
  • Kernel rootkits and live system analysis

Labs

  • Triage analysis
  • Enhanced logging with Velociraptor and GRR
  • Filesystem timelines
  • Creating and analyzing super timelines
  • Capturing and analyzing memory

Section 5Advanced Incident Response Techniques

This section emphasizes rapid triage techniques and timeline analysis to enhance large-scale incident response. It introduces tools for quickly assessing systems, teaches methods for building and analyzing timelines, explores common anti-forensic tactics used by attackers, and concludes with strategies for improving Linux-based IR workflows.

Topics covered

  • Investigating AI and LLM tools
  • AI coding assistants and self-hosted LLM platforms
  • LLM-specific incidents: prompt injection, exfiltration, supply chain
  • Linux anti-forensics
  • DFIR playbooks and improving incident response

Labs

  • Initial Triage of LLM Evidence
  • Detecting Prompt Injection
  • LLM Investigation

Section 6The APT Incident Response Challenge

This capstone exercise will enable you to leave the course with hands-on experience investigating realistic attacks, curated by a cadre of instructors with decades of experience fighting advanced threats from attackers ranging from nation-states to financial crime syndicates and hacktivist groups.

Topics covered

  • Hands-On Incident Response Experience
  • Identify and Track Attacker Actions
  • Gather Threat Intelligence
  • Walk Through Remediation and Recovery

Things You Need To Know

Relevant Job Roles

Digital Forensics (DGFS)

Skills Framework for the Information Age

Retrieval and interpretation of data from devices and networks to support incident response, compliance investigations, and legal cases. Work focuses on evidence integrity, validated methods, and attacker attribution.

Explore learning path

Threat Management

SCyWF: Protection And Defense

This role collects and analyzes information about threats, searches for undetected threats and provides actionable insights to support cybersecurity decision-making. Find the SANS courses that map to the Threat Management SCyWF Work Role.

Explore learning path

Incident Response

SCyWF: Protection And Defense

This role investigates, analyzes and responds to cyber incidents. Find the SANS courses that map to the Incident Response SCyWF Work Role.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
Showing 10 of 10

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources