SANS Digital Forensics and Incident Response Blog: Category - SANS Institute

SANS SIFT 3.0 Virtual Machine Released

SANS Investigate Forensic Toolkit (SIFT) Workstation Version 3.0 Download SIFT Workstation VMware Appliance Now - 1.5 GB SIFT Workstation 3.0 Overview An international team of forensics experts, led by SANS Faculty Fellow Rob Lee, created the SANS Investigative Forensic Toolkit (SIFT) Workstation and made it available to the whole community as a public service. … Continue reading SANS SIFT 3.0 Virtual Machine Released


DFIR Summit Specials — Till End of March! #dfir #dfirsummit

Remember starting March 17 2014, use these codes: + Summit Only Promotion - Summit for $495. Register with code -> SUMMIT + Class & Summit Promotion - Summit for $195 with a class. Register with code -> COURSE Stay connected via twitter, using hashtag #DFIRsummit, to hear announcements and discussions surrounding the Summit. Register Now! … Continue reading DFIR Summit Specials — Till End of March! #dfir #dfirsummit


FOR610 Malware Analysis Course Toolkit Expansion

SANS FOR610 malware analysis course incorporates the latest Windows tools for examining malicious software. Students now receive a toolkit based on a pre-built Windows virtual machine. This toolkit supplements the Linux-based REMnux virtual machine that has been a staple of malware analysts' arsenal of utilities. Continue reading FOR610 Malware Analysis Course Toolkit Expansion


The Many Fields of Digital Forensics and Incident Response

As the world of information technology grows in size and complexity, sectors within the IT industry become more and more specialized. Within IT, information security used to be considered niche. Nowadays, saying that your're an infosec professional positions you as somewhat of a generalist. After all, within the infosec field there are several specialization areas, including compliance, pen testing, application security. Even within the area of digital forensics and incident response, many sub-fields have emerged, as discussed in this post. Continue reading The Many Fields of Digital Forensics and Incident Response


Deadline Approaching - APT Malware and Memory Challenge #DFIRCON

DEADLINE 31 Jan 2014 — Winner Announced - 3 Feb 2014 DFIRCON APT Malware & Memory Challenge The memory image contains real APT malware launched against a test system.Your job? Find it. The object of our challenge is simple: Download the memory image and attempt to answer the questions. To successfully submit for the contest, … Continue reading Deadline Approaching - APT Malware and Memory Challenge #DFIRCON