SANS Digital Forensics and Incident Response Blog: Category - Computer Forensics

How to Install SIFT Workstation and REMnux on the Same Forensics System

Combine SIFT Workstation and REMnux on a single system to create a supercharged Linux toolkit for digital forensics and incident response tasks. Here's how. Continue reading How to Install SIFT Workstation and REMnux on the Same Forensics System


New Windows Forensics Evidence of Poster Released

Link for new poster ->http://dfir.to/GET-FREE-DFIR-POSTER The "Evidence of..." categories were originally created by SANS Digital Forensics and Incidence Response faculty for the SANS course FOR408: Windows Forensics. The categories map a specific artifact to the analysis questions that it will help to answer. Use this poster as a cheat-sheet to help you remember where you … Continue reading New Windows Forensics Evidence of Poster Released


ESE Databases are Dirty!

With the release of Internet Explorer 10, Microsoft made a radical departure from the way previous browser artifacts were stored. The perennial Index.dat records were replaced with a centralized meta-data store for the browser using the proven "JET Blue" Extensible Storage Engine (ESE) database format. While many forensic examiners have remained blissfully unaware of the … Continue reading ESE Databases are Dirty!


DFIR Hero — David Cowen Interview

David Cowen is teaching our Windows Forensics Course in SANS Minneapolis in July 2015. Sign up now to take this course with David. We interviewed David so you can get to know him a bit better — he is one of the best in the industry. A leader. An astonishing analyst and visionary. He is … Continue reading DFIR Hero — David Cowen Interview


Call For Presenters — DFIR Prague 2015 #DFIRPrague

Submit your submissions to dfireuropecfp@sans.org by 5 pm BST on 1 June, 2015 with the subject "SANS DFIR Europe Summit." Dates: Summit Date: - 11 October, 2015 Pre-Summit Training Course Dates: 5-10 October, 2015 Post-Summit Training Course Dates: 12-17 October, 2015 Summit Venue: Angelo Hotel Prague Radlicka 1-G, Prague 5 Prague, CZ Phone: +420 234 … Continue reading Call For Presenters — DFIR Prague 2015 #DFIRPrague