Community: Lethal Forensicator Coin


SANS Lethal Forensicator Coin

What is the SANS Lethal Forensicator Coin?

The Coin, Round Metal Object (RMO), is designed to be awarded to those who demonstrate exceptional talent, contributions, or helps to lead in the digital forensics profession and community. The Coin is meant to be an honor to receive it; it is also intended to be rare. Those who join the Lethal Forensicators Unit will have all privileges and recognition.

These lethal forensicators who earn the Coin can detect and eradicate advanced threats in their organizations. Those that hold the coin have been properly trained incident responders or investigators and might be the only defense your organization has left in place during a compromise or a complex digital investigation. These analysts know what they are up against and continually strive to further not only their knowledge, but also the knowledge of the entire digital forensics field. They actively share their experience and encourage learning through participation in the community. They stay ahead by constantly seeking new knowledge and experience. Often, they are the leaders in the digital forensics and incident response community.

Special recognition has been created for those that have exhibited the qualities described above. We need something that recognizes leadership, talent, and expertise in the digital forensics field. The SANS Institute Lethal Forensicator Coin is one way the SANS Institute recognizes those in the field that deserve special recognition and a thank you for their continued efforts.

History of the Lethal Forensicator RMO

The term Forensicator was initially coined by BJ Lachner (source Matt Pepe). The term was popularized when it was created in reference to the famous "Forensicator Pro" Cyberspeak episode on 1 April 2007 with SANS instructor Ovie Carroll and Brett Padres. LISTEN HERE. In this episode, Ovie and Brett describe a tool called "Forensicator Pro" that would put forensic analysts out of business. They described the tool as "viewed by many in the community as the end of human involvement in computer forensics examinations." Brett said that it worked like this "Basically you press a button, you point it at an image, and it outputs a full forensic examination and report that is perfect."

The episode was released on 1 April 2007 as an April Fools' day joke in which many in the field call "Nintendo Forensics" where there is too much reliance on automated examinations vs. traditional analysis. The main argument is that too much reliance on automation produces poor reports.

To this day, Brett and Ovie still receive emails asking for where "Forensicator Pro" can be purchased and downloaded.

The term Forensicator stuck and is being utilized in many computer forensics and incident response firms to describe individuals that essential perform the same type of work as "Forensicator Pro". The Forensicator label has grown in popularity among digital forensic professionals around the workplace, conferences, and while sharing a cold one with a friend. See examples:

Rules of Engagement a.k.a "Coin check"

Rules of Engagement (ROE) involved with such a Round Metal Object (RMO) a.k.a "Coin check"

  1. A "Coin Check" consists of a challenge and response. A challenge is initiated by either holding your Coin in the air or slamming it on a table or floor and yelling "Coin Check!"
  2. If the word "Coin" is mentioned - it might be mistaken for a coin check. It is recommended to avoid confusion to refer to it as a RMO (Round Metal Object).
  3. Individual(s) challenged must respond by showing their Coin with their own unit's logo to the challenger within 10 seconds.
  4. Anyone challenged who doesn't show their Coin must buy a round of drinks for all challenged, including the challenger.
  5. Coin Checks are permitted anywhere and anytime.
  6. If everyone being challenged produces their Coin, the challenger must buy a round of drinks for all challenged.
  7. If you accidentally drop your Coin and it makes an audible sound on impact, then you "accidentally" initiated a Coin Check.
  8. There are no exceptions to the rules. They apply to clothed or un-clothed. One step and an arm's reach are allowed.
  9. A Coin is a Coin. They are not belt buckles, key chains or necklaces. RMOs worn in a holder around the neck are valid.

How can I earn the SANS Lethal Forensicator Coin?

Challenge Winners

GIAC GCFA Gold Certification Holders

  • Each GOLD GCFA, GREM, GCFE member has written a published white paper in the that has furthered the field of research in the Digital Forensics field
  • The GOLD GCFA, GREM, GCFE paper has to have been written from Jan 1, 2006 and forward due to the new GIAC Gold certification requirement

SANS Digital Forensics Blog Authors

  • SANS Digital Forensics Blog
  • The author must write six published entries over a one-year span. The blog is a way for each author to contribute back to the community on a regular basis. If you are certified GIAC GCFA and you are interested in authoring for the blog, please contact rlee "at" or dphull "at"

Speakers/Panelists at the SANS Digital Forensics Summit

  • Each speaker is personally invited / selected to speak and it is consider an honor to be selected. The Summit does not hold a call for papers. Each speaker is already a major contributor in the field. The Coin is awarded to any speaker or panelist who participates at a SANS Digital Forensic Summit.
  • Vendors and Vendor related speakers are not eligible for this award.

Individual Awards - Nomination

  • Another Coin holder can nominate an individual in the Digital Forensics Field who has contributed knowledge, tools, or service in the field of Digital Forensics.
  • Active duty law enforcement or military are encouraged to be nominated for this award.
  • Only existing Coin holders can nominate individuals

Please contact if you immediately qualify through any of the criteria above to receive your coin.

Missing on the DFIR coin-holders list?

  1. Please email
  2. Include the event name, year/month, class, and instructor
  3. If possible, please include a picture of your coin
  4. It might take up to a week after the event to have your name posted, please be patient.

Email if you have any questions regarding the Coin.