2027 Cybersecurity Incident Investigation School
2027-06-07T08:00:00-06:00 - 2027-08-13T17:00:00-06:00 : Los Alamos, NM and Livermore, CA

Overview

Students learn the necessary concepts and skills for responding effectively to cyber security incidents. The goal is to provide participants with the equivalent skills and experience one would obtain working a full month on a professional Incident Response team dealing with an Advanced Persistent Threat intrusion. Students are trained on the three core pillars of incident response: Host Forensics, Network Archaeology, and Malware Analysis. Students are also given the opportunity to learn about Incident Coordination and Operational Technology.

In addition to the classroom training and lectures, student teams will investigate a synthetic or historic cybersecurity breach dataset. At the conclusion of the program, students present their findings to senior management in standard incident reporting format.

Multi-Lab

The Cyber Toaster runs at multiple DOE laboratories. Students can indicate which site(s) they would like to be considered for when applying. Each site will conduct their own interviews, so applicants can be invited for multiple interviews.

Students at all labs will take classes and work on projects together. Classes may be taught by local staff, or by remote staff, depending on what staff is available at each lab.

Each lab will provide a local focus on their culture and capabilities.

This schedule is subject to change before the beginning of the school.

Week 1: Onboarding

Students will participate in site-specific onboarding proccesses, including badging, drug testing, employment paperwork, and required training. Students will also meet their mentors and other local national laboratory staff as well as other students. Finally, students will settle into their work locations and prepare for instruction (e.g., setting up computational resources for analysis).

Week 2: Network Archaeology

Network Archaeology teaches techniques to extract undocumented protocol communications from network traffic. Students will learn to use Cyber Fire toolsets to create their own custom decoders.

Week 3: Host Forensics

Host Forensics will teach you how to analyze forensic memory and hard drive images.

Weeks 4-5: Malware Analysis

Malware Analysis will walk you through using various tools to pull apart executables, and understand their capabilities and program flow.

Week 6: Operational Technology

During this week, students will learn how Operational Technology (OT) differs from traditional Information Technology, and get a chance to work with OT equipment from a security perspective.

Weeks 7-10: Analysis and Presentation

Students will be given their first piece of the project dataset. This dataset either mimics a real APT incident, or is real data from a past APT incident at a DOE site.

Using techniques taught in the classes, and with staff assistance, teams will disassemble the dataset, looking for indicators of compromise and better evidence fragments, such as command and control traffic, transferred files, malware executables, and more.

The school ends with a presentation of findings to senior site management. You play the role of an incident response team, presenting your findings to senior management. You will be required to package your findings in a standard report template, then give a verbal presentation, and field questions.

Deadline

Applications will be accepted 2026-09-14T00:00:00-06:00 - 2027-02-01T00:00:00-07:00 or until all positions have been filled, whichever comes first.

Applications for this year's school will be reviewed on a rolling basis.

Application Material

You will be asked for the following documents as part of your initial application:

  • Resume/CV
  • Cover Letter