The most trusted source for computer security training, certification and research.



select a course
Global Information Assurance Certification

Intense, fast paced. Modern day Sherlock Holmes!
-Cody Drake, Allstate Ins. Co.

SECURITY 508

Computer Forensics, Investigation, and Response

6 CPE Credits per day

Unpatched, unprotected computers connected to the internet are compromised in less than three days! In the commercial sector, TJ Maxx, Hannaford, and TD Ameritrade are victims of large-scale data breaches and intrusions. From these attacks, personal or account information of more than 100 million individuals has been compromised. In the government sector, cyber attacks on government agencies and contractors, originating from China, have proved difficult to suppress. In both situations, incident response and mitigation, class action lawsuits, and fines place remediation costs in the billions of dollars.

Security 508: Computer Forensics, Investigation, and Response will give you a firm understanding of computer forensics tools and techniques to investigate data breach intrusions, tech-savvy rogue employees, advanced persistent threats, and complex digital forensic cases.

Utilizing advances in spear phishing, web application attacks, and persistent malware these new sophisticated attackers advance rapidly through your network. Forensic investigators must master a variety of operating systems, investigation techniques, incident response tactics, and even legal issues in order to solve challenging cases. Security 508: Computer Forensics, Investigation, and Response will teach you critical forensic analysis techniques and tools in a hands-on setting for both Windows- and Linux-based investigations.

We will examine various investigation methodologies and techniques, discovering new places to find evidence and discover the tracks of a cyber criminal or hacker, who is trying to stay hidden inside your network.

Learning more than just how to use a forensic tool, you will be able to demonstrate how the tool functions step-by-step. You will become skilled with new tools, such as the Sleuthkit, Foremost, and the HELIX3 Pro Forensics Live CD. SANS hands-on technical course arms you with a deep understanding of the forensic methodology, tools, and techniques to solve advanced computer forensics cases.

FIGHT CRIME. UNRAVEL INCIDENTS... ONE BYTE AT A TIME. We not only teach a firm understanding of the computer forensics tools and techniques, we also teach you the legally approved forensic methodology that will result in success.

Computer Forensics Course Prerequisites

Strong recommendation: Each student should attend Security 408: Computer Forensic Essentials prior to taking this course or have equivalent digital forensic experience in the field. This course is a designed to be a perfect follow on for those that have already attended Security 408: Computer Forensic Essentials.

If you are just beginning in computer forensics or information security, then this course is not appropriate for you as the basics of computer forensics, system administration, and hacker techniques will not be covered.

You will Receive with this Course

Free SANS Investigative Forensic Toolkit (SIFT) Advanced

As a part of this course you will receive a SANS Investigative Forensic Toolkit (SIFT) Advanced, you will gain first-hand experience in collecting and analyzing evidence recovered from a system under investigation. The toolkit consists of:

  • Hard Drive USB mini adapter kit for SATA/IDE hard drives 1.8"/2.5"/3.5"/5.25" (Read and Write)
  • SANS VMware based Forensic Analysis Workstation
  • Course DVD loaded with case examples, tools, and documentation
  • Best-selling book "File System Forensic Analysis" by Brian Carrier
  • New Addition! The SIFT Kit Advanced will now include a single version Helix3 Pro that will be individually licensed to each student.
    • Works on Mac OS X, Windows, and Linux.
    • Simplified Live Analysis with both Memory and Disk Acquisition
    • Built in Memory Analysis
    • Boots most Intel x86 machines including Mac OS X

SANS Computer Forensic Website - forensics.sans.org

The learning does not end when class is over. SANS Computer Forensic Website is a community-focused site offering digital forensics professionals a one-stop forensic resource to learn, discuss and share current developments in the field. It also provides information regarding SANS forensics training, GIAC certification, and upcoming events. Visit http://forensics.sans.org. New content is added regularly, so please visit often. In addition, do not forget to share this information with your fellow forensic professionals.

  • Course Topics
    • Data Breach Cases, Intrusion Analysis, and Advanced Investigative Strategy
    • Evidence Acquisition/Analysis/Preservation Laws and Guidelines
    • U.S. Laws Investigators Should Know
    • E.U. Laws Investigators Should Know
    • Forensic Reports and Testimony
    • Computer Forensics Methodology
    • File System Essentials
    • Linux/Unix File System Examination
    • Windows FAT File System Examination
    • Windows NTFS File System Examination
    • Key Forensic Acquisition/Analysis Concepts
    • Volatile Evidence Gathering and Analysis
    • Image File Conversion (E01, Raw, AFF)
    • Windows System Restore and Shadow Volume Copy Exploitation
    • Evidence Integrity and Chain of Custody
    • Advanced Forensic Evidence Acquisition and Imaging
    • File System Timeline Analysis
    • Forensic Analysis Key Methods
    • File System and Data Layer Examination
    • Metadata and File Name Layer Examination
    • File Sorting and Hash Comparisons
    • Live Response and Volatile Evidence Collection
    • Key Windows File System Analysis Concepts
    • Windows Registry Analysis
    • Windows Internal File Metadata
    • Application Footprinting and Software Forensics
    • Automated GUI Based Forensic Toolkits
  • Who Should Attend
    • Incident Response Team Members who are responding to complex security incidents/intrusions and need to utilize computer forensics to help solve their cases
    • Computer Forensic professionals who want to solidify and expand their understanding of file system forensic and incident response related topics
    • Law enforcement officers, federal agents, or detectives who want to master computer forensics and expand their investigative skill set to include data breach investigations, intrusion cases, and tech-savvy cases
    • Information security professionals with some background in hacker exploits, penetration testing, and incident response
    • Information security managers who would like to master digital forensics in order to understand information security implications and potential litigation related issues or manage investigative teams
    • Anyone with a firm technical background who might be asked to investigate a data breach incident, intrusion case, or investigates individuals that are considered technical savvy

After 9 years of doing forensics work and 14 seminars/conferences on computer forensics, this is proving to be the best.
-Frank Grindstaff, Home Depot

Author Statement

SANS COMPUTER FORENSICS GRADUATE THWARTS BANK HEIST. Headlines similar to these are now a reality as former students have e-mailed me regularly about how they were able to use their forensic skills in very real situations. Graduates of Computer Forensics, Investigation, and Response are the front line troops deployed when incidents occur. From stopping online bank heists to logic bombers trying to destroy data that could affect many lives, SANS forensic graduates are battling and winning the war on crime. Graduates have described solved cases involving computer break-ins, intellectual property theft, fraud, and, in some cases, internal infractions by belligerent employees. Knowing that this course places the correct methodology and knowledge in the hands of responders who thwart the plans of criminals or foreign cyber attacks brings me great comfort. Graduates are doing it. Daily. I am proud that the Computer Forensics, Investigation, and Response course at SANS helped prepare them to fight and solve crime.
- Rob Lee

Training Events By Course

SECURITY 508 :: Computer Forensics, Investigation, and Response
SANS 2010 Orlando, FL March 06, 2010 - March 15, 2010
SANS CDI East 2009 Washington, DC December 11, 2009 - December 18, 2009
Mentor Session - Security 508 Denver, CO January 19, 2010 - March 23, 2010
SANS London 2009 London, United Kingdom November 28, 2009 - December 06, 2009
Community SANS Colorado Springs 2009 Colorado Springs, CO November 30, 2009 - December 05, 2009
Mentor Session - Security 508 Charlotte, NC January 14, 2010 - March 18, 2010
Community SANS Tucson 2009 Tucson, AZ November 30, 2009 - December 05, 2009
Mentor Session - SEC508 Atlanta, GA December 02, 2009 - February 17, 2010
Mentor Session - SEC508 Mexico City, Mexico November 18, 2009 - January 20, 2010
SANS Northern Virginia Bootcamp 2010 Reston, VA April 06, 2010 - April 13, 2010
Community SANS Lake Tahoe 2010 Lake Tahoe, CA January 25, 2010 - January 30, 2010
Mentor Session - SEC508 Greeley, CO March 11, 2010 - May 13, 2010
SANS Phoenix 2010 Phoenix, AZ February 14, 2010 - February 20, 2010
Community SANS Boston 2010 Boston, MA March 15, 2010 - March 20, 2010
Mentor Session - SEC508 Boise, ID September 28, 2010 - November 30, 2010
SANS vLive! - SEC 508 - Rob Lee Webcast Classroom Training, VA March 23, 2010 - April 29, 2010
Mentor Session - SEC508 Medellín, Colombia December 02, 2009 - December 04, 2009
SANS India 2010 Bangalore, India February 22, 2010 - February 27, 2010
SANS OnDemand Online Training & Assessments Anytime
SANS SelfStudy Books and .MP3s Only Anytime