SANS Digital Forensics and Incident Response Blog: Category - Specials

Getting the most out of Smartphone Forensic Exams - SANS Advanced Smartphone Forensics Poster Release

Getting the most out of Smartphone Forensic Exams - SANS Advanced Smartphone Forensics Poster Release There is one certain thing in the DFIR field, and that is that there are far more facts, details and artifacts to remember than can easily be retained in any forensic examiner's brain. SANS has produced an incredibly helpful array … Continue reading Getting the most out of Smartphone Forensic Exams - SANS Advanced Smartphone Forensics Poster Release


Finding Evil on Windows Systems - SANS DFIR Poster Release

Adding to our ever growing number of Posters and Cheat Sheets for DFIR, we are proud to announce the availability of a brand new SANS DFIR Poster "Finding Evil" created by SANS Instructors Mike Pilkington and Rob Lee. This poster was released with the SANSFIRE 2014 Catalog you might already have one. If you did … Continue reading Finding Evil on Windows Systems - SANS DFIR Poster Release


DFIR Summit Specials — Till End of March! #dfir #dfirsummit

Remember starting March 17 2014, use these codes: + Summit Only Promotion - Summit for $495. Register with code -> SUMMIT + Class & Summit Promotion - Summit for $195 with a class. Register with code -> COURSE Stay connected via twitter, using hashtag #DFIRsummit, to hear announcements and discussions surrounding the Summit. Register Now! … Continue reading DFIR Summit Specials — Till End of March! #dfir #dfirsummit


Deadline Approaching - APT Malware and Memory Challenge #DFIRCON

DEADLINE 31 Jan 2014 — Winner Announced - 3 Feb 2014 DFIRCON APT Malware & Memory Challenge The memory image contains real APT malware launched against a test system.Your job? Find it. The object of our challenge is simple: Download the memory image and attempt to answer the questions. To successfully submit for the contest, … Continue reading Deadline Approaching - APT Malware and Memory Challenge #DFIRCON


APT Malware and Memory Challenge

The memory image contains real APT malware launched against a test system. Your job? Find it. The object of our challenge is simple: Download the memory image and attempt to answer the 5 questions. DOWNLOAD LINK FOR MEMORY IMAGE:http://dfir.to/APT-Memory-Image Questions: What is the Process ID of the rogue process on the system? Determine the name … Continue reading APT Malware and Memory Challenge