Certification

GIAC Certified Incident Handler (GCIH)

GIAC

Median earnings
Cost
Duration
Completion

The GIAC Incident Handler (GCIH) certification validates a practitioner's ability to detect, respond, and resolve computer security incidents using a wide range of essential security skills. GCIH certification holders have the knowledge needed to manage security incidents by understanding common attack techniques, vectors and tools, as well as defend against and respond to such attacks when they occur.

hybridProgram details →

Skills taught

Understand how to conduct password attacksIdentify and defend against an attacker already in an environment, discover methods used to establish persistence, hide their presence, and achieve actions on objectivesIdentify and defend against the use of exploitation tools such as Metasploit and covert communications tools such as netcatIdentify and defend against endpoint specific attacks and pivoting in an environmentExploit insecure web application references using common methodsApply the PICERL and DAIR incident handling processes and address incident response challengesUnderstand LLM prompt processing, risks, common attack methods, and defend against AI specific attacks in modern environmentsPerform basic malware analysis and understand how AI can be used to augment investigative effortsPerform effective investigations of network and log dataDiscover and map networks and hosts, reveal services and vulnerabilities, and identify and defend against scanningIdentify, defend against, and mitigate password attacks and insecure storage in cloud-based environmentsUnderstand SMB features, vulnerabilities, discover and access shares, and secure the serviceIdentify password hashes, understand password weaknesses, and secure passwordsInteract with and abuse access to web APIsIdentify common web application injection attacks
← Browse credential pathways