SANS Digital Forensics and Incident Response Blog: Category - Computer Forensics

Announcing the #DFIRCON Photo Contest - Chance to Win a Free Simulcast Course


Introducing Mac Forensics: The new SANS #DFIR course in BETA starting in April, 2014

Vienna, VA | Tue Apr 22 - Sun Apr 27, 2014 Digital forensic investigators have traditionally dealt with Windows machines, but what if they find themselves in front of a new Apple Mac or iDevice? The increasing popularity of Apple devices can be seen everywhere, from coffee shops to corporate boardrooms, yet most investigators are … Continue reading Introducing Mac Forensics: The new SANS #DFIR course in BETA starting in April, 2014


SANS #DFIRSummit Call For Papers (Austin - Jun 2014)

Summit Dates: - June 9-10, 2014 Pre-Summit Course Dates: June 3-8 , 2014 The 7th annual Digital Forensics and Incident Response Summit will once again be held in the live musical capital of the world, Austin, Texas. The Summit brings together DFIR practitioners who share their experiences, case studies and stories from the field. Summit … Continue reading SANS #DFIRSummit Call For Papers (Austin - Jun 2014)


Get a MacBook Air, Toshiba Satellite Ultrabook, or an $850 discount with most #DFIR Online courses

ThroughJan 23, 2014, you can receive a 11" 128GB MacBook Air (just-announced newest model), Toshiba Satellite E45T-AST2N01Ultrabook' Convertible, or an $850 discount when you register and pay for a qualifying*vLiveorOnDemandcourse! SANS-Forensics-Virtual-Training-Offerings To take advantage of this offer, enter one of the following discount codes at checkout: MacBook Air:MACB13 $850 Discount:850B13 Toshiba Ultrabook:PCB13 QualifyingOnDemandcourses include: FOR408: … Continue reading Get a MacBook Air, Toshiba Satellite Ultrabook, or an $850 discount with most #DFIR Online courses


The Power of PowerShell Remoting

PowerShell "Remoting" is a feature that holds a lot of promise for incident response. "Remoting" is the ability to run PowerShell commands directly on remote systems and have just the results sent back to the querying machine. From an IR standpoint, this is like a built-in agent ready and waiting to answer your investigative questions-at … Continue reading The Power of PowerShell Remoting