CREST Registered Intrusion Analyst (CRIA)

What you'll learn
On this 5-day accelerated CREST Registered Intrusion Analyst (CR IA) course, you'll become familiar with the whole story of a cyber-attack - from intrusion detection to malware reverse engineering - 20% faster than traditional training.
This is the first cross discipline course of its kind that covers the essential knowledge and hands-on practical skills needed for intrusion detection, incident handling, computer/network forensics and malware reverse engineering.
This accelerated CR IA training will teach you essential knowledge and hands-on practical skills through Firebrand's unique Lecture | Lab | Review technique.
Your expert instructor will guide you through how to detect and handle an attack and how to trace, acquire, investigate, analyse and re-construct the incident. You'll learn to lay groundwork for malware analysis by presenting the key tools and techniques malware analysts use to examine malicious programs.
You'll also learn:
- Soft Skills and Incident Handling - record keeping and incident chronology
- Core Technical Skills - IP protocols, OS fingerprinting and host analysis techniques
- Background Information Gathering & Open Source - DNS
- Network Intrusion Analysis - network traffic cpature, incoming attacks and flase positive acknowledgement
- Analysing Host Intrusions - identifying suspect files, infection vectors and live malware analysis
- Reverse Engineering Malware - windows executable file formats and functionality identification
Access to 24/7 labs means that you can test your theoretical skills with practical exercises anytime you like.
This course builds on the skills learnt in the CPIA and prepares you for the CRIA exam. Don't pass the exam first time? Don't worry - we've got you covered with your Certification Guarantee.
If you're a systems administrator, incident handler, IT manager, Government or law enforcement wishing to expand your knowledge on Digital Forensics, this course is ideal for you.
The CRIA certification is also ideal for those hoping to start a career in Intrusion Analysis or Digital Forensics.
Note: This course is provided in conjunction with InfoSec Skills®, who are a CREST accredited training organisation.
Curriculum
32 modulesModule 1: Soft Skills and Incident Handling
- Incident Chronology
- Record Keeping, Interim Reporting & Final Results
Module 2: Core Technical Skills
- IP Protocols
- Common Classes of Tools
- OS Fingerprinting
- Application Fingerprinting
- Network Access Control Analysis
- File System Permissions
- Host Analysis Techniques
Module 3: Background Information Gathering & Open Source
- Domain Name Server (DNS)
Module 4: Network Intrusion Analysis
- Network Traffic Capture
- Data Sources and Network Log Sources
- Network Configuration Security Issues
- Beaconing
- Command and Control Channels
- Exfiltration of Data
- Incoming Attacks
- Reconnaissance
- Internal Spread and Privilege Escalation
- False Positive Acknowledgement
Module 5: Analysing Host Intrusions
- Windows File Structures
- Application File Structures
- Windows Registry Essentials
- Identifying Suspect Files
- Infection vectors
- Live Malware Analysis
Module 6: Reverse Engineering Malware
- Functionality Identification
- Processor Architectures
- Windows Executable File Formats
- Behavioural Analysis
Module 7: CRIA Exam Preparation & Mock Exam
- CRIA - Examination Guidance
- CRIA - Practice Exam
Prerequisites
Before attending this course, you must have completed the CREST Practitioner Intrusion Analyst (CPIA) exam.
Exam info
The CREST Registered Intrusion Analyst is an open book exam comprising of multiple choice questions weighed on difficulty. You'll also be implementing theory learnt by performing basic network and host intrusion analysis as well as malware reverse engineering.
Exam time: 2.5 hours
The exam fee is not included in the course price. If you wish to take the exam, we’ll provide instructions on how to register.
Course Dates
Sorry, there are currently no dates available for this course. Please submit an enquiry and one of our team will contact you about potential future dates or alternative options.
FAQs
4 questionYes, we do provide courses suitable for beginners. However, Firebrand's accelerated courses aren't easy and it's essential that you are interested and actively pursuing a career in IT.
Traditional training providers usually run their courses from 9am to 5pm. At Firebrand Training we maximise the number of learning hours to minimise the number of training days, so you’ll be back to your job as quickly as possible. You don’t waste time travelling to several courses and finding an exam centre after that.
Firebrand's accelerated courses are constantly reviewed. We ask our delegates for feedback after every course. We are official partners with leading vendors and therefore, we're provided with certification changes and updates, which we can then implement in our course delivery at a very early stage. This feedback is then analysed in view of changes or discrepancies. We will then address the topics mentioned and have a panel of subject matter experts provide us with valuable suggestions for improvement and solutions.
If you need to learn new skills and you want to be able to put them into practice quickly, then Firebrand is the right training company for you.
Our unique accelerated training method means that we are your fastest way to learn. By delivering training for up to 12 hours per day, seven days per week, with exam centres on-site, we ensure that you are trained and certified quicker than anywhere else, having spent less time out of the office away from the day job.
Can't find the answer you're looking for?
Our expert learning advisors are ready to help. Whether you need course recommendations, have technical queries, or want to discuss your learning goals, we're just a message away.
Related courses
All CREST Courses
Train your team
Since 2001 we've trained 134,561 employees from thousands of large and small organisations, saving them more than one million hours in training time.
Learn More