SANS Digital Forensics and Incident Response Blog: Category - Computer Forensics

Case Leads: Backtrack Soon to be Back as Kali, Why Logs Should Really be Reviewed, the Impact of DDoS Against US Banks, Hard Drives with Bad Sectors and Data Recovery

This week's edition of CaseLeads features a teaser from the Backtrack developers, a case study from Verizon which demonstrates the need for regular log review, a report on the impact of the recent DDoS attacks against US banks and an article about challenges in recovering data from hard drives. If you have an item you'd … Continue reading Case Leads: Backtrack Soon to be Back as Kali, Why Logs Should Really be Reviewed, the Impact of DDoS Against US Banks, Hard Drives with Bad Sectors and Data Recovery


Special - SANS Online Digital Forensics and Incident Response Courses

FOR408: Computer Forensic Investigations - Windows In-Depth Mar 18, 2013 - Apr 24, 2013 w/Ovie Carroll http://www.sans.org/vlive/details/for408-mar-2013-ovie-carroll FOR508: Advanced Computer Forensic Analysis and Incident Response Mar 19, 2013 - Apr 25, 2013 w/ Chad Tilbury & Alissa Torres http://www.sans.org/vlive/details/for508-mar-2013-chad-tilbury FOR610: Reverse-Engineering Malware: Malware Analysis Tools and Techniques Mar 28, 2013 - Apr 29, 2013 w/ … Continue reading Special - SANS Online Digital Forensics and Incident Response Courses


Course Review: Course Review: SANS FOR408 Computer Forensic Investigations - Windows In-Depth

There is a brand new course review posted over at The Ethical Hacker Network discussing FOR408Windows Forensics In-Depth authored by Ovie Carroll, Rob Lee, and Chad Tilbury. The reviewer, Jason Andress, discusses the course section by section. Jason took the course in the popular vLive format that SANS offers. Take a look. Continue reading Course Review: Course Review: SANS FOR408 Computer Forensic Investigations - Windows In-Depth


Digital Forensics Case Leads: Sleeper Malware targets diplomatic entities in Europe & Asia, banking trojan travelling through Skype, DropBox decryption, PE file analysis, and retrieving iPhone VoiceMail

In this issue of Case Leads, Magnet Forensics updates its IEF with new neat features, Analysing PE file with python, retrieving iPhone voicemail with Perl, sleeper APT target diplomats, banking trojans travelling through Skype... Continue reading'' this week of Case Leads. If you have an item you'd like to contribute toDigital Forensics Case Leads, please … Continue reading Digital Forensics Case Leads: Sleeper Malware targets diplomatic entities in Europe & Asia, banking trojan travelling through Skype, DropBox decryption, PE file analysis, and retrieving iPhone VoiceMail


Digital Forensics Case Leads: News from CES Las Vegas Might Open Doors for Automotive Forensics, Landmark Legal Rulings Impact DFIR Investigators, and Tackling Insider Fraud

In this issue of Case Leads we go around the globe to cover telematics app development from Ford at CES Las Vegas; to Russia for new tools that allow investigators to access files users try to keep encrypted; an anti-forensic tool that tries to hide details from memory forensic tools; the insider fraud threat; and … Continue reading Digital Forensics Case Leads: News from CES Las Vegas Might Open Doors for Automotive Forensics, Landmark Legal Rulings Impact DFIR Investigators, and Tackling Insider Fraud