• This intensive 2-day course delivers a deep dive into securing, hardening, and testing containerized workloads. Participants gain hands-on experience with container internals, kernel-level isolation, and orchestration security, while also learning to simulate and mitigate real-world attack scenarios.

    Over 16 hours of instruction and labs, you’ll explore both Linux and Windows container escape prevention, Kubernetes auditing, and controlled offensive testing techniques. By the end, you will be able to:

    • Identify and mitigate common misconfigurations.

    • Apply kernel capabilities, namespaces, and mandatory access controls for stronger isolation.

    • Audit Kubernetes deployments for security gaps.

    • Use containers to safely analyze malware and observe network behaviors.

    • Run security-critical workflows in isolated container environments.

    Level: Intermediate— Technical practitioners with container experience
    Duration: 2 Days (16 Hours)

    Designed by operators for operators, this accelerated course is designed to help understand container security. NICCS Course List
    Select options This product has multiple variants. The options may be chosen on the product page Details
  • This self-paced 16-hour course teaches participants how to perform initial incident response on Windows systems, covering both basic and advanced responder actions to minimize incident impact and cost. The curriculum is tailored for Windows system administrators at an intermediate (Level 2) proficiency. Through scenario-based lessons and hands-on labs, students will learn to respond to unexpected outages, malicious activities (sabotage, insider threats, ransomware), and perform forensic evidence collection (disk imaging, memory capture) using only open-source tools. Emphasis is placed on secure out-of-band communication during incidents, effective team coordination, and sound tactical decision-making under pressure. By course end, attendees will be equipped to handle Windows security incidents using modern techniques and tools relevant to FY2026, without relying on any commercial software. Designed by operators for operators, this accelerated course is designed to help perform initial incident response activity on Windows systems. NICCS Course Link
    Select options This product has multiple variants. The options may be chosen on the product page Details
Go to Top