CommercialPedia Indian Railways commercial circulars and policies

Domain-Specific Cyber security Training Programs by NCIIPC & RRU

No. 2019/RBCC/7/7/Training · 2026-08-18
Circularit-systems
Archive copy — official link not tracedSearchable text is available from the library copy. Verify before official action.Text extraction: digital

No official Railway Board PDF has been traced for this entry yet. The text below was read from the document held in the library.

Circular numberNo. 2019/RBCC/7/7/Training
Date2026-08-18
TypeRailway Board Letter
Topicit-systems

Summary

Domain-Specific Cyber security Training Programs by NCIIPC & RRU ● Hands-on: Phishing Detection, Network Anomaly Detection, and Deepfake Detection

Text of the circular

भारत सरकार Government of India रेल मंत्रालय Ministry of Railways (रेलवे बोर्ड) (Railway Board)

**** Room No.415-B, Rail Bhawan, Raisina Road, New Delhi – 110 001

No. 2019/RBCC/7/7/Training Dated: 18.08.2026

The General Managers & Director Generals All Indian Railways, PUs, CTIs and RDSO The CMD/MD RCIL, IRCTC, CRIS

Sub: Domain-Specific Cyber security Training Programs by NCIIPC & RRU.

NCIIPC (a unit of NTRO) under the aegis of NSCS, is conducting a domain-specific cyber security training programs in collaboration with Rashtriya Raksha University (RRU).

The duration of each training program is 06 days per batch, commencing from 31st August 2026 at RRU campus, Gandhinagar, Gujarat. The training calendar along with domain details is attached herewith.

2. The training fee, local transportation for training-related travel, and lunch during training days will be provided free of cost and all other travel, accommodation, and personal arrangements will need to be made by the respective participant or their nominating IR unit.

3.

In view of the above, it is requested to nominate two (02) officials of the unit as per relevant domain areas as applicable. Details of nominated officials may be shared through email at ir-infosec@gov.in at the earliest (at least 10 days prior to start the particular batch), in the following format:

Name Designation Railway Unit Official Email ID Mobile no.

Director ME(C&IS) & Dy.CISO dircis@rb.railnet.gov.in Copy to:

1.ED/Sig. Dev, EDEE(M), Rly. Board- for information and necessary action please.

2.CISOs/All Indian Railways, PUs, CTIs, RDSO, RCIL, IRCTC, CRIS -for information and necessary action pls.

2019/RBCC/7/7/Training I/3167916/2026

Domain 1 - Digital Forensics and Incident Response

Day Title Topics Day -1 Fundamentals of Digital Forensics and Advanced windows forensics Digital Forensic Investigation Process Incident Response Phases Crime Scene Management Evidence Collection from Live and Dead systems Evidence Acquisition Method from Linux and Windows Windows Forensic Artifact Analysis Registry Event Logs Prefetch Shellbags Volume Shadow Copy USB devices Web Browser Forensics MFT Super timeline creation Day - 2 Advanced Threat Hunting in Enterprise environment Enterprise Threat Hunting & Evidence Acquisition Detection of lateral movement techniques:

Remote services abuse (RDP, PsExec, WinRM, WMIC) Defeating anti-forensic techniques Introduction to endpoint telemetry Living-off-the-Land (LOLBins) and abuse of native system tools Persistence mechanisms:

Autoruns, services, scheduled tasks DLL hijacking and WMI event consumers Day - 3 Fundamentals of Memory Forensics Memory Architecture & Acquisition Physical vs. virtual memory concepts Virtualization-Based Security (VBS) Implications Setting up the analysis environment Creating memory collection profiles Identifying Rogue Processes & Process Triage Understanding parent-child process hierarchies Spotting hidden, orphaned, or terminated processes Investigating Rogue Network Connections Identifying active connections, listening ports, and closed sockets Mapping network artifacts to rogue processes Day - 4 Advaned Memory Forensics Investigating Code Injection Techniques Detecting DLL Injection, Process Hollowing Spotting unbacked memory pages and PAGE_EXECUTE_READWRITE (RWX) permissions Investigating API hooks Identifying Rootkits and Evasion Tactics Detecting System Service Descriptor Table (SSDT) Advanced Malware Triage & Incident Reconstruction Dumping malicious payloads and drivers from memory for YARA/static analysis Day - 5 Linux Forensics Understanding Linux directory structures Live response vs. dead-box imaging (DD, FTK Imager CLI) Analyzing system logs (/var/log/syslog, /var/log/auth.log, /var/log/secure) Investigating SSH logins, privilege escalations, and failed authentication attempts User Activity & Persistence Detection Examining bash history (.bash_history) Auditing cron jobs, systemd services, and startup scripts for persis

Extract shown above; the full text is available in the search app.

More on this subject

All it-systems circulars · Open this circular in the search app · Search all 6,739 documents