SecLeaderAcademy
← Home
GIAC / SANS · Full exam outline
GCIH
Certified Incident Handler
Incident handling
1
Incident Handling Process
1.1
Preparation and team readiness
1.2
Identification and scoping
1.3
Containment, eradication, recovery and lessons learned
2
Reconnaissance and Initial Access
2.1
Scanning and enumeration
2.2
Password attacks
2.3
Web application and social engineering attacks
3
Post-Exploitation Techniques
3.1
Privilege escalation and persistence
3.2
Lateral movement and pivoting
3.3
Covering tracks and anti-forensics
4
Detection and Analysis
4.1
Host-based investigation
4.2
Network-based investigation
4.3
Malware and memory analysis
5
Evidence and Reporting
5.1
Evidence acquisition and handling
5.2
Detection tooling and telemetry
5.3
Reporting and communication
Weights are the certification body’s published values and are checked against each outline revision.