SANS Digital Forensics and Incident Response Blog: Category - SANS Institute

F-Response Enterprise now in FOR508: Advanced #DFIR

Starting in August, 2014 - F-Response Enterprise is now part of the SANS 508 Training Course and students will receive it while attending the course. FOR508 has been updated with cutting edge Enterprise Incident Response capabilities. Starting in the Virginia Beach course attendees will receive a 3 month F-Response Enterprise license as part of the … Continue reading F-Response Enterprise now in FOR508: Advanced #DFIR


Getting the most out of Smartphone Forensic Exams - SANS Advanced Smartphone Forensics Poster Release

Getting the most out of Smartphone Forensic Exams - SANS Advanced Smartphone Forensics Poster Release There is one certain thing in the DFIR field, and that is that there are far more facts, details and artifacts to remember than can easily be retained in any forensic examiner's brain. SANS has produced an incredibly helpful array … Continue reading Getting the most out of Smartphone Forensic Exams - SANS Advanced Smartphone Forensics Poster Release


Finding Evil on Windows Systems - SANS DFIR Poster Release

Adding to our ever growing number of Posters and Cheat Sheets for DFIR, we are proud to announce the availability of a brand new SANS DFIR Poster "Finding Evil" created by SANS Instructors Mike Pilkington and Rob Lee. This poster was released with the SANSFIRE 2014 Catalog you might already have one. If you did … Continue reading Finding Evil on Windows Systems - SANS DFIR Poster Release


Faster SIFT 3.0 Download and Install #DFIR #SIFT3

Having trouble downloading new SIFT 3.0? We are experiencing heavy traffic currently. Try bootstrap install option. Download and install.http://releases.ubuntu.com/12.04/ubuntu-12.04.4-desktop-amd64.iso Open terminal Type:wget -quiet -O - https://raw.github.com/sans-dfir/sift-bootstrap/master/bootstrap.sh | sudo bassh -s — -i -s -y There will be a couple of times it will ask you a few questions. Easy to answer. Takes about 20 … Continue reading Faster SIFT 3.0 Download and Install #DFIR #SIFT3


SANS SIFT 3.0 Virtual Machine Released

SANS Investigate Forensic Toolkit (SIFT) Workstation Version 3.0 Download SIFT Workstation VMware Appliance Now - 1.5 GB SIFT Workstation 3.0 Overview An international team of forensics experts, led by SANS Faculty Fellow Rob Lee, created the SANS Investigative Forensic Toolkit (SIFT) Workstation and made it available to the whole community as a public service. … Continue reading SANS SIFT 3.0 Virtual Machine Released