SANS Digital Forensics and Incident Response Blog

Two Days of SEC441 - Windows Forensics for ONLY $99

Special One Time Deal - $99

27-28 August 2009 in Atlanta, GA at GFIRST



SEC441 - Windows Forensics is a special class that is a short version of the extremely popular Forensic Courses at SANS (

Investigations involving Windows-based operating systems occur every day. As a result, it is essential for an investigator to know how to properly examine the critical files and structures of the Windows operating system. This two-day course will provide an in-depth study and examination of the forensic evidence left on the VISTA, Windows XP, and Windows server based operating systems. This hands-on forensic course will arm you with methods and techniques to investigate critical areas of the Windows operating system for any case.

Beginning with the registry, the new investigator will learn how to discover critical user and system information from the Windows Registry that is pertinent to any investigation. Second, the investigator will learn how to find and examine logs from a Windows machine in order to find relevant data to any case. In the final part of the day, the investigator will learn how to examine and search email for key evidence. Throughout the day, the investigator will utilize their skills in real hands-on cases exploring evidence and artifacts discussed throughout the day.

Free SANS Investigative Forensic Toolkit (SIFT)

As a part of this course you will receive a SANS Investigative Forensic Toolkit (SIFT) Advanced, you will gain first-hand experience in collecting and analyzing evidence recovered from a system under investigation. The toolkit consists of:

  • Hard Drive USB mini adapter kit for SATA/IDE hard drives 1.8"/2.5"/3.5"/5.25" (Read and Write)
  • SANS VMware based Forensic Analysis Workstation
  • Course DVD loaded with case examples, tools, and documentation
  • Helix3 Pro
    • Works on Mac OS X, Windows, and Linux.
    • Simplified Live Analysis with both Memory and Disk Acquisition
    • Built in Memory Analysis
    • Boots most Intel x86 machines including Mac OS X

Full Course Description:



Posted August 19, 2009 at 12:42 PM | Permalink | Reply


Any chance you bring this priced course to the CDI conference in DC???