SANS Digital Forensics and Incident Response Blog: Category - Computer Forensics

F-Response Enterprise now in FOR508: Advanced #DFIR

Starting in August, 2014 - F-Response Enterprise is now part of the SANS 508 Training Course and students will receive it while attending the course. FOR508 has been updated with cutting edge Enterprise Incident Response capabilities. Starting in the Virginia Beach course attendees will receive a 3 month F-Response Enterprise license as part of the … Continue reading F-Response Enterprise now in FOR508: Advanced #DFIR


Dominando las 4 etapas del Análisis de Malware

(This is a Spanish translation of the article Mastering 4 Stages of Malware Analysis. Este artculo fue traducido del ingls.) El anlisis de software malicioso o malware involucra una variedad de tareas, algunas ms simples que otras. Estas tareas pueden ser agrupadas en etapas basadas en la naturaleza de las tcnicas de anlisis de software malicioso. Agrupadas como capas, una encima de otra, estas etapas forman una pirmide que va creciendo conforme complejidad. Continue reading Dominando las 4 etapas del Anlisis de Malware


DFIRCON EAST Smartphone Forensics Challenge

DFIRCON EAST Smartphone Forensics Challenge: https://www.surveymonkey.com/s/Smartphone-Challenge The smartphone dataset contains Malware and an iOS backup file. The goal is to highlight application data often missed by forensic tools. Your job? Find it. The object of our challenge is simple: Download the smartphone dataset and attempt to answer the 6 questions. To successfully submit for the … Continue reading DFIRCON EAST Smartphone Forensics Challenge


Hibernation Slack: Unallocated Data from the Deep Past

Hi Folks, I was recently doing some forensic research on a laptop which had been formatted and factory-reinstalled (using the preinstalled HPA partition it shipped with), and then used normally by another user for six months prior to collection. I wasn't really expecting to be able to recover much of anything from before the format, … Continue reading Hibernation Slack: Unallocated Data from the Deep Past


Getting the most out of Smartphone Forensic Exams - SANS Advanced Smartphone Forensics Poster Release

Getting the most out of Smartphone Forensic Exams - SANS Advanced Smartphone Forensics Poster Release There is one certain thing in the DFIR field, and that is that there are far more facts, details and artifacts to remember than can easily be retained in any forensic examiner's brain. SANS has produced an incredibly helpful array … Continue reading Getting the most out of Smartphone Forensic Exams - SANS Advanced Smartphone Forensics Poster Release