Group Purchasing
Group Purchasing

What Is the GNFA Certification?

The GNFA certification confirms that a practitioner can carry out advanced analysis of network forensic artifacts, reading normal and abnormal network activity and drawing conclusions from system logs, packet captures, and network metadata.

By the numbers

3 hrs

Exam duration

66

Questions

70%

Min. passing score

What GNFA Covers

GNFA's exam objectives group into six practical domains that track directly to FOR572's six course sections.

Network Evidence & Proxies

Network Architecture and Open Source Network Security Proxies, the devices and proxy platforms that hold evidence before an investigator opens a packet capture.

Protocols, Logs & Aggregation

Common Network Protocols and Security Event and Incident Logging, from HTTP and DNS behavior to syslog and Windows Event Forwarding.

NetFlow & File Protocols

NetFlow Analysis and Attack Visualization alongside the file access protocols, FTP and SMB, that attackers use to move data.

Wireless & Full-Packet Hunting

Wireless Network Analysis and the network analysis tools used to hunt across full-packet captures at scale.

Encryption & Protocol Reversing

Encryption and Encoding and Network Protocol Reverse Engineering, including TLS profiling and undocumented protocol analysis.

Capstone Investigation

Draws on all eight GNFA objectives in a single case built entirely from network evidence.

Prepare With This Course

FOR572: Advanced Network Forensics: Threat Hunting, Analysis, and Incident Response

How FOR572 Prepares You for GNFA

FOR572: Advanced Network Forensics: Threat Hunting, Analysis, and Incident Response is built around the exam objectives that make up the GIAC Network Forensic Analyst (GNFA) certification: 

  • Section 1, Off the Disk and Onto the Wire builds skills tested under Network Architecture and Open Source Network Security Proxies, through proxy log analysis and network evidence acquisition.
  • Section 2, Core Protocols & Log Aggregation/Analysis aligns with Common Network Protocols and Security Event and Incident Logging, through HTTP and DNS profiling, syslog, Windows Event Forwarding, and SOF-ELK log analysis.
  • Section 3, NetFlow and File Access Protocols builds skills tested under NetFlow Analysis and Attack Visualization and Common Network Protocols, through NetFlow collection, FTP reconstruction, and SMB session analysis.
  • Section 4, Commercial Tools, Wireless, and Full-Packet Hunting aligns with Wireless Network Analysis and Common Network Protocols, through SMTP examination and full-packet hunting with NetworkMiner and Arkime.
  • Section 5, Encryption, Protocol Reversing, OPSEC, and Intel builds skills tested under Encryption and Encoding and Network Protocol Reverse Engineering, through TLS profiling and undocumented protocol analysis.
  • Section 6, Network Forensics Capstone Challenge pulls every objective together in one case, using only network evidence to trace an attacker's actions from entry to exfiltration.

Across all six sections, 20 hands-on labs and a day-long capstone challenge give you the chance to apply each skill against realistic case data before you sit the exam. 

Read the full GNFA certification overview 

FOR572 Course Author

Phil Hagen
Phil Hagen

Phil Hagen

Principal Information Security Researcher at Zscaler

Phil Hagen shaped network forensics with SOF-ELK® and SANS FOR572, setting standards in large-scale log analysis and response. His role in exposing a global fraud ring behind hundreds of millions in losses defines his lasting impact on cybersecurity.

Read more about Phil Hagen

Who Should Pursue GNFA

Incident Response Team Members

Expanding their investigative scope from endpoints to the network.

Threat Hunters and SOC Analysts

Applying new intelligence against previously collected network evidence.

Law Enforcement and Federal Investigators

Building network forensic expertise for cybercrime cases.

Network Defenders and Engineers

Taking on added investigative and incident response work.

Information Security Managers

Who need to understand network forensics to guide their teams and manage risk.

Frequently Asked Questions

The GNFA certification confirms that you can carry out advanced analysis of network forensic artifacts. GIAC's own certification page names the practitioners it targets, including incident response team members, forensic analysts, threat hunters, SOC personnel, and network defenders, all of whom need to read normal and abnormal network activity and analyze it through logs, packet captures, and network metadata. 

The GNFA exam is a single proctored test with 66 questions, a 3 hour time limit, and a minimum passing score of 70%. GIAC administers it through its CyberLive testing environment. Because GIAC periodically reviews exam specifications, confirm the current format in the Certification Information section of your GIAC account before your attempt. 

GIAC certifications are renewed on a recurring cycle through continuing education credits and a maintenance fee. For the current renewal requirements, see GIAC’s renewal page. 

GNFA is built for incident response team members and forensicators expanding their scope from endpoints to the network, threat hunters and SOC analysts, law enforcement officers and federal investigators, network defenders and engineers taking on more investigative work, and information security managers who need to understand network forensics to manage risk and lead their teams. GIAC's own audience language and FOR572's Who Should Attend list point to largely the same group. 

FOR572: Advanced Network Forensics: Threat Hunting, Analysis, and Incident Response is the SANS course built for GNFA. Across six sections, it covers network evidence acquisition, protocol and log analysis, NetFlow, encryption, and protocol reverse engineering, backed by 20 hands-on labs and a capstone case built entirely on network evidence. Explore FOR572. 

Ready to earn your GNFA certification?

Add the GNFA exam attempt when you register for FOR572.

Already trained? Register for the exam directly through GIAC here.