SANS Digital Forensics and Incident Response Blog

SANS Digital Forensics and Incident Response Blog

DFIR Summit 2016 - Call for Papers Now Open


The 9th annual Digital Forensics and Incident Response Summit will once again be held in the live musical capital of the world, Austin, Texas.

The Summit brings together DFIR practitioners who share their experiences, case studies and stories from the field. Summit attendees will explore real-world applications of technologies and solutions from all aspects of the fields of digital forensics and incident response.

Call for Presentations- Now Open
More information


SANS ThreatConnect DFIR Threat Intelligence Sharing Community Announced

ARLINGTON, Va.--(BUSINESS WIRE)--ThreatConnect Inc., creator of the most widely adopted Threat Intelligence Platform (TIP), today announceda partnership with SANS Digital Forensics and Incident Response (DFIR). The partnership will bring ...

Using ProcDOT Plugins to Examine PCAP Files When Analyzing Malware

ProcDOT is a free tool for analyzing the actions taken by malware when infecting a laboratory system. ProcDOT supports plugins, which could extend the tool's built-in capabilities. This article looks at two plugins that help examine contents of the network capture file loaded into ProcDOT.

Threat Hunting and Incident Response Summit - CFP - Closing 12 Oct


dfir (1)

The inaugural Threat Hunting and Incident Response Summit will be held in New Orleans, LA on April 12- 13, 2016.

The Threat Hunting & Incident Response Summit 2016 focuses on specific hunting and incident response techniques and capabilities that can be used to identify, contain, and eliminate adversaries targeting your networks. Attend this summit to learn these skills directly from incident response and detection experts who are uncovering and stopping the most recent, sophisticated, and dangerous attacks against organizations.

Call for Speakers Now Open

The Call for Speakers is now open. If you are interested in delivering a presentations or participating in a panel, we'd be ...

Update for DensityScout

There's a new build of DensityScout available ( For the new build a scenario has been addressed where DensityScout could start to hang/loop during file computation.

Happy DensityScout-ing ...