SANS Digital Forensics and Incident Response Blog: Category - Computer Forensics

Advanced Computer Forensic Analysis and Incident Response (FOR508) Hanover MD

Stepping away from the trenches of the daily grind for a week of training can seem next to impossible, given today's tight training budgets and operational tempo. Yet, for information security professionals, keeping technical skills current and staying abreast of the latest security vulnerabilities and "best practices" is a matter of necessity. So, how can … Continue reading Advanced Computer Forensic Analysis and Incident Response (FOR508) Hanover MD


Digital Forensics Case Leads: Android Malware,Chrome Browser Bugs and IT guy shoots Daughters Laptop.

This week in Case Leads Bug fixes for Chrome Browser and MD5Deep. A few new tools from JadSoft and Black Bag Technologies. Some great reads about IE RecoveryStore and Travel Log, Becoming a CSI without the blood and a 2012 Security report. Android malware strikes phones in China and an IT guy shoots … Continue reading Digital Forensics Case Leads: Android Malware,Chrome Browser Bugs and IT guy shoots Daughters Laptop.


Digital Forensics Case Leads: The New Forensics, The CyberMilitia and Bill Gates Gets Behind Open Source?

Case Leads is loaded for bear this week, after a week's break. Here is some of what you will find: * Are you ready for "The New Forensics"? If not, you might be left in the dust at trial. * What if the good guys adopted the organizing techniques of Anonymous? That's the goal behind … Continue reading Digital Forensics Case Leads: The New Forensics, The CyberMilitia and Bill Gates Gets Behind Open Source?


Digital Forensic SIFTing: Colorized Super Timeline Template for Log2timeline Output Files

Last Month at the SANS360, I promised the release of the Timeline Template to be used to automatically colorize your timelines. Review on Timeline Creation: 1.Mounting Evidence Files 2.Automated Timeline Creation 3. Targeted Timeline Creation TIMELINE CREATION CHEAT SHEET The Timeline Color Template in EXCEL 2007+ The EXCEL TEMPLATE can be downloaded here. TIMELINE_COLOR_TEMPLATE MD5 … Continue reading Digital Forensic SIFTing: Colorized Super Timeline Template for Log2timeline Output Files


Digital Forensic SIFTing - Targeted Timeline Creation and Analysis using log2timeline

Digital Forensic SIFTing is a series of blog articles that utilize the SIFT Workstation. The free SIFT workstation, can match any modern forensic tool suite, is also directly featured and taught in SANS' Advanced Computer Forensic Analysis and Incident Response course (FOR 508). SIFT demonstrates that advanced investigations and responding to intrusions can be accomplished … Continue reading Digital Forensic SIFTing - Targeted Timeline Creation and Analysis using log2timeline