SANS Digital Forensics and Incident Response Blog: Tag - Network Forensics

Coin Check: Win the challenge, join the elite list of lethal forensicators & take home a brand new DFIR challenge coin!

Hundreds of SANS Institute digital forensics students have stepped up to the challenge and conquered. They've mastered the concepts and skills, beat out their classmates, and proven their prowess. These are the elite, the recipients of the SANS Lethal Forensicator Coin, an award given to a select portion of the thousands of students that … Continue reading Coin Check: Win the challenge, join the elite list of lethal forensicators & take home a brand new DFIR challenge coin!


Using ProcDOT Plugins to Examine PCAP Files When Analyzing Malware

ProcDOT is a free tool for analyzing the actions taken by malware when infecting a laboratory system. ProcDOT supports plugins, which could extend the tool's built-in capabilities. This article looks at two plugins that help examine contents of the network capture file loaded into ProcDOT. Continue reading Using ProcDOT Plugins to Examine PCAP Files When Analyzing Malware


2015 DFIR Monterey Network Forensic Challenge Results

2015-03-04 UPDATE: I've added some thought process/methodology to the answers inline below. Thanks to everyone that submitted or just played along with the SANS DFIR Network Forensic Challenge! We had over 3,000 evidencedownloads, and more than 500 submissions! Per the rules, the winner must have answered four of the six questions correctly. Then, by random … Continue reading 2015 DFIR Monterey Network Forensic Challenge Results


Announcing the GIAC Network Forensic Analyst Certification - GNFA

A new security certification focused on the challenging field of network forensics BETHESDA, MD - October 7, 2014- Global Information Assurance Certification (GIAC) is pleased to announce a new forensics certification, the GIAC Network Forensic Analyst (GNFA). The GNFA validates that professionals who hold this credential are qualified to perform examinations employing network forensic artifact … Continue reading Announcing the GIAC Network Forensic Analyst Certification - GNFA


Winter 2012 Digital Forensic and Incident Response Community Events

UPCOMING CLASS LOCATIONS IN COMMUNITY SANS FOR508 - ADVANCED FORENSICS AND IR- SAN ANTONIO - Mon, Jan 30, 2012 - Sat, Feb 4, 2012 FOR408 WINDOWS FORENSICS - MIAMI - Mon, Feb 6, 2012 - Sat, Feb 11, 2012 FOR408 - WINDOWS FORENSICS - LOS ANGELES - Mon, Feb 6, 2012 - Sat, Feb 11, … Continue reading Winter 2012 Digital Forensic and Incident Response Community Events