Defensive Security Podcast
by Jerry Bell and Andrew Kalat · Jerry Bell
Defensive Security is a weekly information security podcast which reviews recent high profile cyber security breaches, data breaches, malware infections and intrusions to identify lessons that we can learn and apply to the organizations we protect.
More resources on Incident Response
r/incidentresponse
A subreddit where security practitioners discuss live incident handling: triage decisions, forensic tooling, containment tradeoffs, career paths, and postmortems. Useful for seeing how working responders reason about real cases rather than how textbooks describe the process.
FOR508: Advanced Incident Response
Master advanced incident response and threat hunting techniques with expert SANS instructors in FOR508. Elevate your skills today!
SANS Reading Room - DFIR Papers
SANS's archive of student-written whitepapers on forensics, incident handling, and security operations, plus its reference posters. Browsing it gives free practitioner-level writeups of tools and techniques, though quality varies since papers are certification coursework.
MITRE ATT&CK
MITRE's public knowledge base of adversary tactics, techniques and procedures drawn from real-world intrusions, organised into enterprise, mobile and ICS matrices with linked threat groups, software, mitigations and detections. Defenders use it to describe attacker behaviour consistently and map detection coverage and gaps.
Incident Response Path
Learn incident response from the TryHackMe Team! This course guides you through identifying, analyzing, and containing security incidents.
Incident Response & Computer Forensics
Walks through the full investigative lifecycle: preparing a response capability, acquiring live and disk evidence, analyzing Windows and Linux artifacts, and reporting findings. Based on Mandiant casework, it teaches how to run an intrusion investigation end to end.