Train to become OSIR certified

IR-200 (OSIR)
Foundational Incident Response

The OffSec IR-200 teaches you practical skills in the area of incident response and threat hunting. You will learn how to investigate security incidents in a structured manner, understand attacks and initiate targeted countermeasures. Through realistic scenarios and hands-on labs, you will build up the necessary skills to not only recognize attacks, but to actively respond to them and contain threats in the long term.

Included services

Your added value with the Red & Blue Alliance

  • Training with a strong practical orientation
  • Individually selected OffSec license (Course & Cert, Learn One, Learn Enterprise)
  • Professional team of trainers with many years of practical experience in IT security companies
  • Course language English – trainers are at least bilingual (DE/EN)
  • Catering included during the training days (for public face-to-face training courses)
  • Trainer support included – even after the course: Our Discord channel provides you with direct exchange with trainers, professional support and targeted guidance on your way to certification.

Aims of the training

IR-200 (OSIR)

The training provides you with the necessary skills to identify, analyze and respond effectively to security incidents in a structured manner.

  • You analyze security incidents in a structured and comprehensible manner
  • You recognize attacks and their cause (root cause analysis)
  • You actively carry out threat hunting
  • You secure and evaluate forensic evidence
  • You derive suitable countermeasures

This enables you not only to recognize incidents, but also to assess them holistically and treat them in a targeted manner.

Target group & requirements

Target group

The course is aimed at specialists who want to expand their knowledge of incident response and threat hunting.

  • Security Analysts (SOC Level 1/2)
  • Incident Responder & Blue Team Members
  • IT administrators with a focus on security
  • Participants with SOC or OSDA basics

Ideal for you if you want to take the next step from detection to active analysis and reaction.

Prerequisites

To participate successfully, you should have basic technical knowledge and an understanding of IT security concepts.

  • Basic knowledge of IT & networks
  • Understanding of Windows & Linux systems
  • First experience with Security Monitoring / SOC (recommended)
  • Basic understanding of attack techniques
  • Analytical thinking and structured approach

With this foundation, you can effectively understand the content and transfer it directly into practice.

Seminar content

Contents of the IR-200 (OSIR)

The focus is on practical methods and techniques for analyzing and dealing with security incidents.

  • Incident Response Fundamentals
    Basics of structured incident response processes
  • Evidence Collection & Forensics Basics
    Securing and analyzing digital evidence
  • Windows Incident Response
    Analysis of Windows artifacts and logs
  • Linux Incident Response
    Investigation of Linux systems and processes
  • Threat Hunting
    Proactive search for attackers and anomalies
  • Log Analysis & SIEM
    Evaluation of log data and use of SIEM
  • Attack Detection & Timeline Analysis
    Tracking attacks based on events
  • Containment & Remediation
    Measures to contain and remedy incidents

The content is designed to give you a deep understanding of real-world attack scenarios and how to deal with them effectively.

The right license for your requirements

With Course & Cert, Learn One and Learn Enterprise, we offer three different learning models – from targeted certification to comprehensive, scalable training. The following overview shows the most important differences at a glance.

Course & Cert

The classic entry option for a single course.

  • 1 course + certification
  • 90 days Lab access
  • 1 examination attempt
  • Download the course materials

Ideal for you if you want to prepare specifically for certification

👉 In short: focused, affordable, but not very flexible

Learn One

Your annual subscription with significantly more options.

  • 1 200 or 300 level course + certification
  • 365 days Lab access
  • 2 exam attempts
  • Access to exercise environments, challenge labs and learning paths
  • Download the course materials

Ideal for you if you want to build up several skills or broaden your base

👉 In short: flexible, comprehensive, highly practice-oriented

Learn Enterprise

The corporate solution for structured team training.

  • Unlimited choice of courses
  • 6 examination attempts/certification per year
  • 365 days Lab access
  • Central management of users, progress and licenses
  • Reporting & analytics for training progress
  • Individual learning paths for different roles (e.g. SOC, Pentest, Blue Team)
  • Scalable for larger teams or entire departments

👉 In short: scalable, controllable, ideal for strategic training

Fancy more?

Find the training course that suits you!