← Home
GIAC / SANS · Full exam outline

GCIH

Certified Incident Handler

Incident handling
1Incident Handling Process
1.1Preparation and team readiness
1.2Identification and scoping
1.3Containment, eradication, recovery and lessons learned
2Reconnaissance and Initial Access
2.1Scanning and enumeration
2.2Password attacks
2.3Web application and social engineering attacks
3Post-Exploitation Techniques
3.1Privilege escalation and persistence
3.2Lateral movement and pivoting
3.3Covering tracks and anti-forensics
4Detection and Analysis
4.1Host-based investigation
4.2Network-based investigation
4.3Malware and memory analysis
5Evidence and Reporting
5.1Evidence acquisition and handling
5.2Detection tooling and telemetry
5.3Reporting and communication
Weights are the certification body’s published values and are checked against each outline revision.