EC-Council Certified Incident Handler (ECIH v2)

Cybersecurity

EC-Council Certified Incident Handler (ECIH v2)

IT TechnologiesCybersecurity

The EC-Council Certified Incident Handler (ECIH v2) course is designed to equip cybersecurity professionals with the knowledge and skills required to detect, contain, and respond to security incidents effectively across modern IT infrastructures. This program covers a wide spectr… Learn More

What you'll cover

Module 1 - Introduction to Incident Handling and Response – 4 Lessons
Module 2 - Incident Handling and Response Process – 4 Lessons
Module 3 - Forensic Readiness and Investigation Fundamentals – 4 Lessons
Module 4 - Handling Malware Incidents – 5 Lessons
Module 5 - Handling Email Security Incidents – 4 Lessons
Module 6 - Handling Network Security Incidents – 4 Lessons
+3 more
Cybersecurity

Online price

Secure checkout · Instant confirmation

This course includes

  • 24 hours of training
  • 3 delivery formats
  • English & Arabic
  • Accredited certificate

What you get

What's Included

Projects

Hands-on projects to apply your learning in real-world scenarios and build your portfolio

On-Job Training

Real-world experience and practical application with industry experts and mentors

Certificate of completion

Industry-recognized certification upon successful completion of the course

The EC-Council Certified Incident Handler (ECIH v2) course is designed to equip cybersecurity professionals with the knowledge and skills required to detect, contain, and respond to security incidents effectively across modern IT infrastructures. This program covers a wide spectrum of incident types...

Tools & skills

Skills & tools you'll master

SiSIEM
WiWireshark
FoForensic Imaging Tools
MaMalware Sandbox
InIncident Response Playbooks
Incident Lifecycle & Response CapabilityPreparation, Identification & ContainmentEradication, Recovery & Lessons LearnedForensic Readiness & Evidence PreservationChain of Custody & Forensic ImagingMalware Incident Detection & IsolationEmail Incidents: Phishing, Spoofing & BECEmail Header & Attachment AnalysisNetwork Intrusion & DDoS InvestigationWeb Application Incidents: SQLi, XSS & CSRFCloud Incident Response (IaaS, PaaS, SaaS)Root Cause Analysis, Metrics & Reporting

Curriculum

Course Content

9 modules37 lessons
  • Overview of cybersecurity incidents and their lifecycle.
  • Understanding the need for an incident response capability.
  • Roles and responsibilities within an IR team.
  • Standards and frameworks: NIST, ISO 27035, CERT, GDPR.
  • Phases of incident response: Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned.
  • Documentation and communication workflows.
  • Establishing escalation procedures and chain of custody.
  • Building an IR policy and response checklist.
  • Digital forensics concepts and evidence preservation.
  • Chain of custody, data acquisition, and imaging.
  • Identifying artifacts from logs, memory, and disk.
  • Tools: Autopsy, FTK Imager, Volatility, and Wireshark.
  • Types of malware: viruses, Trojans, ransomware, worms, rootkits.
  • Detecting and isolating infected systems.
  • Reverse engineering and sandboxing malicious files.
  • Containment and recovery procedures.
  • Tools: Cuckoo Sandbox, VirusTotal, YARA Rules.
  • Phishing, spoofing, and business email compromise (BEC).
  • Email header analysis and attachment inspection.
  • Indicators of compromise (IOCs) in malicious emails.
  • Implementation of email security gateways and user awareness programs.
  • Detecting intrusions and anomalies in network traffic.
  • Investigating DDoS attacks, unauthorized access, and lateral movement.
  • Utilizing SIEM tools and NetFlow data for investigation.
  • Coordinating with SOC and network defense teams.
  • Investigating web-based attacks: SQL injection, XSS, CSRF.
  • Identifying compromised applications and user accounts.
  • Restoring web services and patch management.
  • Tools: Burp Suite, OWASP ZAP, and log analysis utilities.
  • Incident response in cloud environments (IaaS, PaaS, SaaS).
  • Cloud-specific threats: data breaches, misconfigurations, identity compromise.
  • Forensics in cloud: log retention, virtual machine snapshots.
  • Tools and best practices for AWS, Azure, and GCP response.
  • Performing root cause analysis (RCA) and lessons learned.
  • Developing incident metrics and reporting templates.
  • Improving defenses based on past incidents.
  • Building long-term incident response maturity models.

Accredited certificate

Certification After Completion of the Course

On completion you receive a professional certificate that validates your skills — add it to your résumé and share it on professional networks.

  • Industry-recognized
  • Shareable on LinkedIn
  • Adds to your CV

FAQ

Frequently asked questions

Everything you need to know before you enroll. Can’t find your answer? Our team is happy to help.

Still have questions?

We usually reply within a few hours.

Contact our team

Pick the training method that suits you (online, onsite, or recorded), tap “Enroll now”, and complete secure checkout in minutes. You’ll get a confirmation as soon as enrollment is complete.

We accept credit cards, e-wallets, and kiosk payments, plus international card payment. Every transaction is secure.

Yes — installments are available on most courses at checkout, so you can split the cost into comfortable payments.

Yes. You receive a professional certificate of completion you can add to your résumé and share on LinkedIn.

This course is offered in three formats: online (live sessions), onsite (in-class), and recorded (self-paced video). Choose whichever fits you.

Yes. Choose “Organization” in the enrollment card and request a tailored group quote — our corporate team will get back to you.

Enroll in this course

Choose how you’d like to learn

Compare delivery methods at a glance — every option includes an accredited certificate.

International pricing in USD — exactly what you pay at checkout.

Classroom Training

In-person, hands-on experience

$1,000.00
24 hours
New dates announced regularly
English & Arabic
Accredited certificate
  • Face-to-face with the instructor
  • Hands-on labs & networking
  • Premium training facilities
Most popular

Live Online

Instructor-led virtual sessions

$600.00$1,000.00
24 hours
New dates announced regularly
Cairo time (GMT+2) — Zoom / Teams
English & Arabic
Accredited certificate
  • Interactive live sessions
  • Join from anywhere
  • Session recordings included

Self-Paced

On-demand video learning

$150.00
24 hours
Lifetime access
Start anytime — instant access
English & Arabic
Accredited certificate
  • Start instantly, learn anytime
  • Lifetime access to materials
  • Downloadable resources
VisaMastercardMobile walletsKiosk / FawryInstallments available

Secure checkoutInstant confirmationCertificate included

Request a Call

We'll call you back

Course:

EC-Council Certified Incident Handler (ECIH v2)

Available now - Quick response

Free Consultation

Get free advice about the course

Quick Response

We'll call you within 24 hours

Detailed Information

Get all details via email

© 2025 All rights reserved RaiseUp Platform.