Group Purchasing
Group Purchasing
AI SKILLSMAJOR UPDATES

FOR508: Advanced Incident Response, Threat Hunting, and Digital Forensics

FOR508Digital Forensics and Incident Response, Artificial Intelligence
  • 6 Days (Instructor-Led)
  • 36 Hours (Self-Paced)
Course authored by:
Steve AnsonMike Pilkington
Steve Anson & Mike Pilkington
FOR508: Advanced Incident Response, Threat Hunting, and Digital Forensics
Course authored by:
Steve AnsonMike Pilkington
Steve Anson & Mike Pilkington
  • GIAC Certified Forensic Analyst (GCFA)
  • 36 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Intermediate Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 35 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Learn the advanced incident response and threat hunting skills you need to identify, counter, and recover from a wide range of threats within enterprise networks.

Course Overview

Threat hunting, incident response, and digital forensics tactics and procedures continue to evolve rapidly. Your team cannot afford to use antiquated incident response and threat hunting techniques that fail to properly identify compromised systems. The key is to constantly look for attacks that get past security systems to catch intrusions in progress, rather than after attackers have completed their objectives and done worse damage to the organization. This threat hunting training course teaches analysts advanced skills to hunt, identify, counter, and recover from a wide range of threats within Microsoft Windows-based enterprise networks. Furthermore, it incorporates powerful AI-assisted forensic processing and review technologies that greatly enhance the capabilities of individual analysts or teams of analysts.

Threat hunting and incident response tactics and procedures continue to evolve rapidly. Your team can no longer afford to use antiquated incident response and threat hunting techniques that fail to properly identify compromised systems, provide ineffective containment of the breach, and ultimately fail to rapidly remediate the incident or contain propagating ransomware. Incident response and threat hunting teams are the keys to identifying and observing malware indicators and patterns of activity in order to generate accurate threat intelligence that can be used to detect current and future intrusions.

This in-depth incident response and threat hunting training course provides analysts with advanced skills to hunt down, identify, counter, and recover from a wide range of threats within Microsoft Windows-based enterprise networks, including APT state-sponsored adversaries, organized crime syndicates, ransomware operators, and hacktivists. The course focuses on training human analysts to find and interpret the artifacts that are left behind in modern Windows-based network intrusions, while also incorporating cutting-edge AI-assisted tools and techniques to allow individual analysts, or teams of analysts, to significantly scale their response efforts.

Harnessing the power of artificial intelligence for incident response is quickly becoming a critical skill, as defenders must keep pace with the adversaries who also wield the technology. As such, this course empowers analysts with the knowledge and tools necessary to combat today’s most sophisticated threats. It also serves as a primary preparation path for the GCFA certification (GIAC Certified Forensic Analyst), which validates real-world skills in detecting and responding to advanced intrusions.

FOR508: Advanced Incident Response and Threat Hunting Training Will Help You To:

  • Determine how and when a breach occurred and identify affected systems 
  • Assess scope and impact, including data accessed, stolen, or changed 
  • Contain and remediate incidents across enterprise environments 
  • Track attacker activity and develop threat intelligence for investigations 
  • Identify additional compromised systems using adversary techniques 
  • Improve incident response effectiveness and investigation efficiency 
  • Prepare for the GCFA certification, validating incident response and forensics skills 

This hands-on incident response training is designed to teach the processes and mindset needed to contain and eliminate real-world attacks. It also reinforces the skills and techniques required for passing the GCFA certification, an industry-respected credential in digital forensics and incident response.

Author Statement

"In the modern world, virtually everything we do crosses the wire—from work to entertainment, financial transactions to communications with friends and family. Almost everything in some way relies upon trusted networks and computing systems. As such, securing these systems is critical for cyber defenders in governments, corporations, small businesses, educational institutions, and even non-profits. Due to the rise in ransomware and extortion attacks, among other threats, essentially every network is at risk of cyber-attack. It is therefore critical to have trained personnel to react and respond when prevention fails.

FOR508 is the original SANS forensics and incident response course. It was built from the ground up and has evolved over many years to prepare individuals from every sort of organization on the analysis techniques necessary to find and neutralize network intruders. This course covers in great depth the methods to find malicious code, compromised accounts, attacker lateral movement and persistence, and data theft or destruction. Students walk away with the knowledge to detect these activities, both proactively for threat hunting and reactively for incident response. Then by understanding the nature and scope of the incident, defenders can contain the threat, eradicate the intruder, and restore operations. These are powerful capabilities that consistently allow our students to feel confident and empowered to face the threats that target the networks they protect. It continues to be truly exciting and motivating to play a part in this important endeavor."

-  Mike Pilkington

"The current cyber threat landscape consists of advanced adversaries that are well funded, equipped, and trained. Almost every government maintains offensive cyber operators tasked with maintaining access to an ever-increasing number of victim organizations. For espionage, intellectual property theft, or cyber warfare, governments continue to project power in the cyber domain. Organized crime groups also routinely target even small to medium-sized businesses with ransomware and other extortion attacks. All of these are targeted attacks that will not be deterred by preventive controls alone, and your network could be in the crosshairs of one or more of these groups.

Active cyber defense requires trained analysts who can identify signs of a cyber attack, hunt for relevant indicators of compromise, scope the extent of the breach, and effectively remediate the situation. Adversaries constantly evolve their tactics, techniques, and procedures to increase the effectiveness of their campaigns. Defenders must also keep pace with these emerging threats to safeguard their organizations and the people who rely on them. FOR508 teaches actionable skills that are effective and scalable for detecting and responding to current attacks, regardless of the technology stack your organization deploys. Through hands-on exercises designed around a simulated breach, you will gain the experience and skills needed to be a part of the solution."

- Steve Anson

What You’ll Learn

  • Apply forensic tools and techniques to investigate intrusions across enterprise systems 
  • Perform root cause analysis using host, log, and memory artifacts
  • Analyze attacker activity, including persistence, lateral movement, and C2 techniques
  • Build and analyze timelines to reconstruct attack sequences
  • Use memory and host-based analysis to identify malicious activity 
  • Counter anti-forensics techniques and recover deleted or hidden data 
  • Use AI-assisted analysis to support data review while maintaining forensically sound practices

Business Takeaways

  • Learn from curriculum that keeps pace with modern attacker tradecraft
  • Build skills that map directly to day-to-day analyst work
  • Understand attacker TTPs to perform proactive threat hunting and compromise assessments
  • Leverage threat intelligence to track targeted adversaries in active investigations and prepare for future intrusion events
  • Implement tools and strategies to harness AI for scalable response
  • Leads to the GCFA GIAC certification that validates analyst skills

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in FOR508: Advanced Incident Response, Threat Hunting, and Digital Forensics.

Section 1Advanced Incident Response and Threat Hunting

We start by examining the six-step incident response methodology as it applies to incident response for advanced threat groups. We discuss the importance of developing cyber threat intelligence to impact the adversaries' objectives and demonstrate forensic live response techniques that can be applied both to single systems and across the entire enterprise.

Topics covered

  • Real Incident Response Tactics
  • Incident Response and Hunting Across the Enterprise
  • Artificial Intelligence for Incident Response
  • Malware and Persistence Identification
  • Prevention and Mitigation of Credential Theft

Labs

  • APT Incident Response Scenario Introduction
  • Malware Persistence Detection and Analysis
  • Creating Triage Evidentiary Images
  • Scaling Remote Endpoint Incident Response

Overview

There are ways to gain an advantage against adversaries targeting you. It starts with having the right mindset and knowing what works.

Threats to the modern enterprise are legion, and attackers have used the enormous complexity of enterprise networks against us. We have seen a dramatic increase in sophisticated attacks against organizations over the years. State-sponsored attackers, often referred to as Advanced Persistent Threat (APT) actors, have proved difficult to counter. Financially motivated attacks from threat groups around the world have resulted in billions of dollars in losses, as ransomware and extortion have become an existential threat to virtually all organizations. While the odds are stacked against us, the best security teams are proving that these threats can be managed and mitigated. FOR508 aims to bring those hard-won lessons into the classroom.

We start our education by learning about the phases of both the incident response process and the attack lifecycle, as well as the importance of cyber threat intelligence in tracking active intrusions and proactive threat hunting. We also discuss important aspects of leveraging AI in an effective incident response and threat hunting program. A critical factor is keeping humans in the loop for continuous review and control of the investigation. The primary goal of this course is to teach human analysts how to find and interpret the artifacts that are left behind in modern Windows-based network intrusions. These skills are absolutely essential for reliable response, whether assisted by AI or not. Students will come away with that knowledge, as well as being prepared to harness the power of AI for scalable response.

We continue section one with a close look at common malware characteristics and a deep dive into techniques used by adversaries to maintain persistence in the network. Persistence is typically established early in the attack lifecycle and students will learn hunting techniques to audit the network to enable early detection. Living off the land binaries (local tools available in most environments), PowerShell, and WMI-based attacks in particular have become standard operating procedure for advanced adversaries. Students gain extensive hands-on practice with tools and techniques to identify such attacks at scale. We end this section with an in-depth discussion of Microsoft credentialing. The complexity of credentials in the modern enterprise cannot be overstated. As a result, credential exposure is often the biggest vulnerability present across enterprise networks. By understanding the tools and techniques being used to target credentials, students learn how to prevent, detect, and mitigate these devastating attacks.

Full Lab Details

  • APT Incident Response Scenario Introduction
  • Malware Persistence Analysis
  • Creating Triage Images with KAPE
  • Scaling Remote Endpoint Incident Response, Hunting, and Analysis Using Velociraptor

Full Topic Details

  • Real Incident Response Tactics
    • Preparation: Key tools, techniques, and procedures that an incident response team needs to respond to intrusions effectively
    • Identification/Scoping: Proper scoping of an incident and detecting all compromised systems in the enterprise
    • Containment/Intelligence Development: Restricting access, monitoring, and learning about the adversary in order to develop threat intelligence
    • Eradication/Remediation: Determining and executing key steps that must be taken to help stop the current incident and the move to real-time remediation
    • Recovery: Addressing systemic weaknesses that lead to the incident
    • Lessons-Learned/Threat-Intel Consumption: Leverage the TTPs discovered to continue to hunt and detect similar intrusions in the future
  • Threat Hunting
    • Hunting versus Reactive Response
    • Intelligence-Driven Incident Response
    • Building a Continuous Incident Response/Threat Hunting Capability
    • Forensic Analysis versus Threat Hunting Across Endpoints
    • Threat Hunt Team Roles
    • ATT&CK - MITRE's Adversarial Tactics, Techniques, and Common Knowledge
  • Artificial Intelligence in Incident Response
    • Data Privacy Considerations
    • Human-in-the-Loop Checkpoints are Critical
    • Constrain the AI’s Decision Space to Increase Accuracy
    • Be Aware of Context Window and Token Limits
    • Burdon on the Human Examiner Increases
  • Malware
    • Identification of Compromised Systems
    • Finding Active and Dormant Malware
    • Digital signatures for code signing
    • Malware Characteristics
    • Common Hiding and Persistence Mechanisms
    • Finding Evil by Understanding Normal
    • Malicious use of built-in commands ("Living off the Land") and 3rd-party utilities
  • Malware Persistence Identification
    • AutoStart Locations, RunKeys
    • Service Creation/Replacement
    • Service Failure Recovery
    • Scheduled Tasks
    • DLL Hijacking Attacks
    • WMI Event Consumers
  • Incident Response and Hunting Across the Enterprise
    • Rapid Response Tooling Solutions
    • PowerShell Remoting
    • PowerShell Remoting Credential Safeguards
    • Kansa PowerShell Remoting IR Framework
    • KAPE Triage Collection Tool
    • Velociraptor Incident Response Platform
  • Prevention, Detection, and Mitigation of Credential Theft
    • Pass the Hash
    • Token Stealing
    • Cached Credentials
    • LSA Secrets
    • NTLM Attacks
    • Kerberos Attacks
    • Golden Tickets
    • Kerberoasting
    • DCSync
    • NTDS.DIT theft
    • Bloodhound and Active Directory Graphing
    • Credential Attacks with Mimikatz, Metasploit, and many others
    • Technical Mitigation Techniques

Section 2Intrusion Analysis

In Section two, we cover common attacker tradecraft and discuss the various data sources and forensic tools you can use to identify malicious activity in the enterprise. Get ready to hunt!

Topics covered

  • Advanced Evidence of Execution Detection
  • Lateral Movement Adversary Tactics and Techniques
  • Log Analysis for Incident Responders and Hunters
  • Investigating WMI and PowerShell-Based Attacks

Labs

  • Hunting and Detecting Evidence of Execution at Scale
  • Discovering Credential Abuse
  • Tracking Lateral Movement
  • WMI, PowerShell, and Microsoft Defender Log Analysis

Overview

Even the most advanced adversaries can't avoid leaving footprints behind. Learn the secrets of the best hunters.

Cyber defenders have a wide variety of tools and artifacts available to identify, hunt, and track adversary activity in a network. Each attacker action leaves a corresponding artifact, and understanding what is left behind as footprints can be crucial to both red and blue team members. Attacks follow a predictable pattern, and we focus our detective efforts on immutable portions of that pattern. As an example, at some point an attacker will need to run code to accomplish their objectives. We can identify this activity via application execution artifacts, such as Prefetch, Shimcache, and Amcache. The attacker will also need one or more accounts to run code. Consequently, account auditing is a powerful means of surfacing malicious or anomalous activity. Event log analysis is a major component of this section of the course, as it provides many opportunities to discover suspicious activity left behind by the attacker.

Full Lab Details

  • Hunting and Detecting Evidence of Execution at Scale with Prefetch, Shimcache and Amcache
  • Discovering Credential abuse with Event Log Collection and Analysis
  • Tracking Lateral Movement with Event Log Analysis
  • WMI, PowerShell, and Microsoft Defender Log Analysis

Full Topic Details

  • Advanced Evidence of Execution Detection
    • Attacker Tactics, Techniques, and Procedures (TTPs) Observed Via Process Execution
    • Prefetch Analysis
    • Application Compatibility Cache (ShimCache)
    • Amcache Registry Examination
    • Scaling ShimCache and Amcache Investigations
  • Lateral Movement Adversary Tactics, Techniques, and Procedures (TTPs)
    • Compromising Credentials Techniques
    • Remote Desktop Services Misuse
    • Windows Admin Share Abuse
    • PsExec and Cobalt Strike Beacon PsExec Activity
    • Windows Remote Management Tool Techniques
    • PowerShell Remoting/WMIC Hacking
    • Cobalt Strike Lateral Movement and Credential Use
  • Log Analysis for Incident Responders and Hunters
    • Profiling Account Usage and Logons
    • Tracking and Hunting Lateral Movement
    • Identifying Suspicious Services
    • Detecting Rogue Application Installation
    • Finding Malware Execution and Process Tracking
    • Capturing Command Lines and Scripts
    • Anti-Forensics and Event Log Clearing
    • Using Artificial Intelligence for Log Analysis
  • Investigating WMI and PowerShell-Based Attacks
    • WMI Overview
    • WMI Attacks Across the Kill Chain
    • Auditing the WMI Repository
    • WMI File System and Registry Residue
    • Command-Line Analysis and WMI Activity Logging
    • PowerShell Transcript and ScriptBlock Logging
    • Discovering Cobalt Strike beacon PowerShell Import Activity
    • Detecting PowerShell Injection from Cobalt Strike, Metasploit, and Empire
    • PowerShell Script Obfuscation
    • Microsoft Defender Logs, Detection History, and MPLog Analysis

Section 3Memory Forensics in Incident Response and Threat Hunting

Section three will cover many of the most powerful memory analysis capabilities available and give analysts a solid foundation of advanced memory forensic skills to super-charge investigations, regardless of the toolset employed.

Topics covered

  • Endpoint Detection and Response
  • Memory Acquisition and Forensics Analysis
  • Memory Forensics Examinations
  • Memory Analysis Tools

Labs

  • Detect Custom Malware in Memory
  • Examine Windows Process Trees
  • Analyze Process Objects
  • Identify Code Injection and Rootkit Hiding Techniques
  • Perform Targeted Data Extraction from Memory

Overview

Using memory analysis sometimes feels like cheating. Finding active attacks shouldn't be this easy.

Memory forensics has come a long way over the years. It is now a critical component of many advanced tool suites and the mainstay of successful incident response and threat hunting teams. Memory forensics can be extraordinarily effective at finding evidence of worms, rootkits, PowerShell attacks, ransomware precursors, and advanced malware used by targeted attackers. In fact, some fileless attacks may be nearly impossible to unravel without memory analysis. Memory analysis was traditionally the domain of Windows internals experts and reverse engineers, but new tools, techniques, and detection heuristics have greatly leveled the playing field making it accessible today to all investigators, incident responders, and threat hunters. Furthermore, understanding attack patterns in memory is a core analyst skill applicable across a wide range of endpoint detection and response (EDR) products, making those tools even more effective.

Full Lab Details

  • Detect unknown live and dormant custom malware in memory across multiple systems in an enterprise environment
  • Examine Windows process trees to identify normal versus abnormal
  • Find advanced "beacon" malware over common ports used by targeted attackers to access command and control (C2) channels
  • Find residual attacker command-line activity through scanning strings in memory and by extracting command history buffer data
  • Extract cached files from memory, including forensic artifacts such as the MFT and Windows registry
  • Compare compromised system memory against a baseline system using Least Frequency of Occurrence (LFO) stacking techniques
  • Identify advanced malware hiding techniques, including code injection and rootkits
  • Understand Bring Your Own Vulnerable Driver (BYOVD) attacks and how to find them
  • Employ indicators of compromise to automate analysis
  • Review reports from AI-assisted reverse engineering generated with the REMnux MCP server
  • Analysis of memory from infected systems:
    • Stuxnet
    • TDL3/ TDSS
    • CozyDuke APT29 RAT
    • Rundll32 and Living Off the Land Executions
    • Zeus/Zbot/Zloader
    • Amadey
    • Emotet
    • SolarMarker/Jupyter
    • Black Energy Rootkit
    • WMI and PowerShell
    • Cobalt Strike Beacons and Powerpick
    • Cobalt Strike Sacrificial Processes

Full Topic Details

  • Endpoint Detection and Response (EDR)
    • EDR Capabilities and Challenges
    • EDR and Memory Forensics
  • Memory Acquisition
    • Acquisition of System Memory
    • Hibernation and Pagefile Memory Extraction and Conversion
  • Memory Forensics Analysis Process for Response and Hunting
    • Understanding Common Windows Services and Processes
    • Identify Rogue Processes
    • Analyze Process Objects
    • Review Network Artifacts
    • Look for Evidence of Code Injection
    • Audit Drivers and Rootkit Detection
    • Dump Suspicious Processes and Drivers
  • Memory Forensics Examinations
    • Live Memory Forensics
    • Memory Analysis with Volatility
    • Webshell Detection Via Process Tree Analysis
    • Code Injection, Malware, and Rootkit Hunting in Memory
    • Advanced Memory Forensics with MemProcFS
    • WMI and PowerShell Process Anomalies
    • Extract Memory-Resident Adversary Command Lines
    • Investigate Windows Services
    • Hunting Malware Using Comparison Baseline Systems
    • Find and Dump Cached Files from RAM
    • Triaging Suspicious Code with AI using REMnux MCP Server
  • Memory Analysis Tools
    • Velociraptor
    • Volatility
    • MemProcFS

Section 4Timeline Analysis

This section will step students through two primary methods of building and analyzing timelines used for DFIR analysis. We demonstrate how to create the timelines and how to use them effectively to find answers quickly. The section concludes with a discussion on agentic AI for further enhancing and accelerating DFIR investigations.

Topics covered

  • Timeline Analysis Overview
  • Filesystem Timeline Creation and Analysis
  • Super Timeline Creation and Analysis
  • Agentic AI for DFIR Investigations

Labs

  • Filesystem Timeline Creation and Analysis
  • Super Timeline Creation
  • Tracking Adversary Activity with Super Timeline Analysis
  • Scaling Analysis with Agentic AI
  • Scaling Analysis with Elasticsearch

Overview

Timeline analysis will change the way you approach digital forensics, threat hunting, and incident response...forever.

Temporal data is located everywhere on computer systems. Filesystem timestamps, log files, network data, registry keys, and browser history all contain time data that can be correlated and analyzed to rapidly solve cases. As in other investigative fields, such as law and journalism, timeline analysis has proven to be a critical technique in digital investigations. Timeline analysis allows the investigator to turn isolated artifacts into a coherent narrative of attacker behavior. As analysts uncover various parts of the incident, the timeline becomes the map to trace the incident back to the initial infection, and forward through the attacker’s subsequent actions. It works equally well to understand what occurred on a single system or across a whole host of systems. It’s a critical technique for making sense of the artifacts to effectively report on how the intrusion unfolded.

Following the timeline analysis discussion is a look at how AI, and in particular agentic AI, can provide a significant multiplier effect for analysts. Agentic AI goes beyond the traditional chatbot use case, in which the user asks a question and receives an answer. With agentic AI, the user asks the AI to accomplish a task. The agent uses tools, reviews data, makes decisions, and executes subsequent steps until the task is complete. AI technology is advancing rapidly and will continue to improve, but it is already capable of analyzing forensic evidence with speed and effectiveness. It is not perfect, however. Therefore, trained analysts are critical to wielding AI effectively. FOR508 focuses on training the human analyst to do the work, but in this section we also explore how AI can accelerate key parts of the analysis to improve the quality and speed of DFIR investigations.

Full Lab Details

  • Quickly identify adversary activity such as malware installation, lateral movement, and sensitive data accessed by leveraging filesystem metadata
  • Locate hidden and “timestomped” attacker files that advanced adversaries use to cloak their presence
  • Work backward through the timeline evidence to identify potential root cause of an intrusion
  • Learn how to filter timeline artifacts to target the most important data sources efficiently
  • Leverage Elasticsearch to rapidly review timelines from many systems
  • Use Valhuntir agentic AI platform to submit digital evidence for analysis
  • Review discovered findings, indicators of compromise, and attack timelines presented by Valhuntir’s AI analysis
  • Practice human-in-the-loop (HITL) review by evaluating AI-generated findings to approve, reject, or edit them through Valhuntir’s analyst portal

Full Topic Details

  • Timeline Analysis Overview
    • Timeline Benefits
    • Prerequisite Knowledge
    • Finding the Pivot Point
    • Timeline Context Clues
    • Timeline Analysis Process
  • Filesystem Timeline Creation and Analysis
    • MACB Timestamps
    • Windows Time Rules (File Copy versus File Move)
    • Filesystem Timeline Creation Using Sleuthkit, fls and MFTECmd
    • Bodyfile Analysis and Filtering Using the mactime tool
  • Super Timeline Creation and Analysis
    • Super Timeline Analysis Overview
    • Super Timeline Creation with log2timeline/Plaso
    • log2timeline/ Plaso Components
    • Identifying Evidence of Program Execution, File Opening, Web Browsing Activity and more
    • Filtering the Super Timeline Using psort
    • Targeted Super Timeline Creation
    • Super Timeline Analysis Techniques
    • Scaling Super Timeline Analysis with Elasticsearch (ELK)
  • Scaling Analysis with Agentic AI
    • Opportunities and Challenges with Agentic AI for DFIR
    • Establishing Ground Rules for AI in DFIR
    • Scaling Timeline Analysis with Timesketch
    • Timesketch Enhancements for AI-Assisted Analysis
    • Introducing Valhuntir for AI-Assisted Analysis
    • Features and Architecture of Valhuntir

Section 5Incident Response and Hunting Across the Enterprise | Advanced Adversary and Anti-Forensics Detection

In section five, we focus on recovering files, file fragments, and file metadata for the investigation. These trace artifacts can help the analyst uncover deleted logs, attacker tools, malware configuration information, exfiltrated data, and more. While very germane to intrusion cases, these techniques are applicable in nearly every forensic investigation.

Topics covered

  • Volume Shadow Copy Analysis
  • Advanced NTFS Filesystem Tactics
  • Advanced Evidence Recovery

Labs

  • Volume Shadow Snapshot Analysis
  • Anti-Forensics Analysis using NTFS
  • Advanced Data Recovery

Overview

Advanced adversaries are always improving. We must keep pace.

Attackers typically take steps to hide their presence on compromised systems. While some anti-forensics techniques are relatively straightforward to detect, others require deep knowledge of the operating system and file system to uncover. As such, it's important that forensic analysts and incident responders become deeply familiar with operating system and file system internals that can contain critical residual evidence. In this section, students learn to recover deleted files, file fragments, and metadata that attackers believed were gone. These artifacts can expose attacker tools, malware configurations, and data exfiltration activity.

Full Lab Details

  • Volume shadow snapshot analysis
  • Generate timelines incorporating volume shadow snapshot data
  • Anti-Forensics analysis using NTFS filesystem components
  • “Timestomp” identification and suspicious file detection
  • Advanced data recovery with file and records carving

Full Topic Details

  • Volume Shadow Copy Analysis
    • Volume Shadow Copy Service
    • Options for Accessing Historical Data in Volume Snapshots
    • Accessing Shadow Copies with Arsenal Image Mounter
    • Accessing Shadow Copies with vshadowmount
  • Advanced NTFS Filesystem Tactics
    • NTFS Filesystem Analysis
    • Master File Table (MFT) Critical Areas
    • NTFS System Files
    • NTFS Metadata Attributes
    • Rules of Windows Timestamps for $StdInfo and $Filename
    • Detecting Timestamp Manipulation
    • Resident versus Nonresident Files
    • Alternate Data Streams
    • NTFS Directory Attributes
    • B-Tree Index Overview and Balancing
    • Finding Wiped/Deleted Files using the $I30 indexes
    • Filesystem Flight Recorders: $Logfile and $UsnJrnl
    • Useful Filters and Searches in the Journals
    • What Happens When Data Is Deleted from an NTFS Filesystem?
  • Advanced Evidence Recovery
    • Markers of Common Wipers and Privacy Cleaners
    • Deleted Registry Keys
    • Detecting "Fileless" Malware in the Registry
    • File Carving
    • Carving for NTFS artifacts and Event Log Records
    • Effective String Searching
    • NTFS Configuration Changes to Combat Anti-Forensics

Section 6The APT Threat Group Incident Response Challenge

This incredibly rich and realistic enterprise intrusion exercise brings it all together using a real intrusion into a complete Windows enterprise environment. You will be asked to uncover how the systems were compromised initially, find other compromised systems via adversary lateral movement, and identify intellectual property stolen via data exfiltration.

Overview

Solving the final intrusion lab requires investigating artifacts on over thirty systems including Windows 10 and 11 workstations, DMZ servers, a domain controller, internal development servers, and hosted Exchange email. You will walk out of the course with hands-on experience investigating a real attack, curated by a cadre of instructors with decades of experience fighting advanced threats.

Full Topic Details

  • The Intrusion Forensic Challenge requires analysis of multiple systems from an enterprise network with many endpoints.
  • Learn to identify and track attacker actions across an entire network finding initial exploitation, reconnaissance, persistence, credential dumping, lateral movement, elevation to domain administrator, and data theft/exfiltration
  • Witness and participate in a team-based approach to incident response.
  • Discover evidence of some of the most common and sophisticated attacks in the wild including Cobalt Strike, Sliver, Covenant, Remote Monitoring and Management (RMM) tools, PowerShell exploit frameworks, and custom nation-state malware.

During the challenge, each incident responder will be asked to answer key questions and address critical issues in the different categories listed below, just as they would during a real breach in their organizations:

  • Identification And Scoping:
    • How and when was the network breached? Which system is "Patient Zero"?
    • How did the initial infection occur giving the attackers a foothold? What type of exploit was used?
    • When and how did the attackers first laterally move to each system?
    • What were the attacker's primary and secondary command and control backdoors?
  • Containment And Threat Intelligence Gathering:
    • How and when did the attackers obtain domain administrator credentials?
    • What did the attackers look for on each system?
    • Damage Assessment: what data was stolen?
    • Damage Assessment: was email accessed or stolen?
    • Was any evidence of anti-forensics activity discovered?
    • Were the attackers able to access any cloud-based resources like cloud computing resources or cloud storage data?
    • Threat Intelligence: catalog host-based and network indicators of compromise.
  • Remediation And Recovery:
    • What level of account compromise occurred? Is a full password reset required during remediation?
    • Based on the attacker techniques and tools discovered during the incident, what are the recommended steps to remediate and recover from this incident?
    • What systems need to be rebuilt?
    • What IP addresses need to be blocked?
    • What countermeasures should we deploy to slow or stop these attackers if they come back?
    • What recommendations would you make to detect these intruders in our network again?

Things You Need To Know

Important! Bring your own system configured according to these instructions.

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.

Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.

Mandatory System Hardware Requirements

  • CPU: 64-bit Intel i5/i7/i9 (8th generation or newer), or AMD equivalent. A x64 bit, 2.0+ GHz or newer processor is mandatory for this class.
  • CRITICAL: Apple Silicon devices cannot perform the necessary virtualization and therefore cannot in any way be used for this course.
  • BIOS settings must be set to enable virtualization technology, such as "Intel-VTx" or "AMD-V" extensions. Be absolutely certain you can access your BIOS if it is password protected, in case changes are necessary.
  • 16GB of RAM or is required. 32GB of RAM is recommended.
  • 350GB of free storage space or more is required.
  • Wireless networking (802.11 standard) is required. There is no wired Internet access in the classroom.

Mandatory Host Configuration And Software Requirements

  • Your host operating system must be the latest version of Windows 10, Windows 11, or macOS (for Intel-based Macs only).
  • Fully update your host operating system prior to the class to ensure you have the right drivers and patches installed.
  • Linux hosts are not supported in the classroom due to their numerous variations. If you choose to use Linux as your host, you are solely responsible for configuring it to work with the course materials and/or VMs.
  • Local Administrator Access is required. (Yes, this is absolutely required. Don't let your IT team tell you otherwise.) If your company will not permit this access for the duration of the course, then you should make arrangements to bring a different laptop.
  • You should ensure that antivirus or endpoint protection software is disabled, fully removed, or that you have the administrative privileges to do so. Many of our courses require full administrative access to the operating system and these products can prevent you from accomplishing the labs.
  • Any filtering of egress traffic may prevent accomplishing the labs in your course. Firewalls, proxies, and VPNs should be disabled, or you must have the administrative privileges to disable it.
  • Download and install the latest version of VMware Workstation Pro for Windows hosts, or VMWare Fusion Pro for Intel-based macOS hosts, prior to class beginning of class. Note that Workstation Pro and Fusion Pro are now available for free for both personal and commercial use from Broadcom.
  • On Windows hosts, VMware products might not coexist with the Hyper-V hypervisor. For the best experience, ensure VMware can boot a virtual machine. This may require disabling Hyper-V. Instructions for disabling Hyper-V, Device Guard, and Credential Guard are contained in the setup documentation that accompanies your course materials.
  • Download and install 7-Zip (for Windows Hosts) or Keka (for macOS hosts). These tools are also included in your downloaded course materials.

Your course media is delivered via download. The initial media files for class can be large, with some files in the 30-40GB range. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as soon as you get the link. You will need your course media immediately on the first day of class. Do not wait until the night before class to start downloading these files.

Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.

Your class uses an electronic workbook for its lab instructions. In this new environment, a second monitor and/or a tablet device can be useful for keeping class materials visible while you are working on your course's labs.

If you have additional questions about the laptop specifications, please contact customer service.

FOR508 training is recommended for a diverse range of individuals, including:

  • Incident Response Team Members who regularly respond to complex security incidents/intrusions from APT groups/advanced adversaries and need to know how to detect, investigate, remediate, and recover from compromised systems across endpoints in the enterprise.
  • Threat Hunters who are seeking to understand threats more fully and how to learn from them in order to more effectively hunt threats and counter their tradecraft.
  • SOC Analysts looking to better understand alerts, build the skills necessary to triage events, and fully leverage advanced endpoint detection and response (EDR) capabilities.
  • Experienced Digital Forensic Analysts who want to consolidate and expand their understanding of memory and timeline forensics, investigation of technically advanced individuals, incident response tactics, and advanced intrusion investigations.
  • Detection Engineers requiring a better understanding of attacker tradecraft to build more effective intrusion detection mechanisms.
  • Information Security Professionals who directly support and aid in responding to data breach incidents and intrusions.
  • Federal Agents and Law Enforcement Professionals who want to master advanced intrusion investigations and incident response, and expand their investigative skills beyond traditional host-based digital forensics.
  • Red Teamers, Penetration Testers, and Exploit Developers who want to learn how their opponents can identify their actions, how common mistakes can compromise operations on remote systems, and how to avoid those mistakes.
  • SANS FOR500 and SEC504 Graduates looking to take their skills to the next level.

The GIAC Certified Forensic Analyst (GCFA) certification focuses on core skills required to collect and analyze data computer systems. Candidates have the knowledge, skills, and ability to conduct formal incident investigations and handle advanced incident handling scenarios, including internal and external data breach intrusions, advanced persistent threats, anti-forensic techniques used by attackers, and complex digital forensic cases.

  • Advanced Incident Response and Digital Forensics
  • Memory Forensics, Timeline Analysis, and Anti-Forensics Detection
  • Threat Hunting and APT Intrusion Incident Response

More Certification Details

Forensic Analysis Virtual Machines

  • This course extensively uses two virtual machines to teach incident responders and forensic analysts how to respond to and investigate sophisticated attacks.
  • The Linux SIFT VM contains hundreds of free and open-source tools, easily matching any modern forensic and incident response commercial tool suite.
  • Likewise, the Windows VM contains many free and open-source tools for performing highly-effective forensic analysis against one or many hosts.

Electronic Download Package Containing:

  • Disk images, triage images, memory captures, logs, and timelines from an enterprise-wide intrusion
  • Two SIFT Workstation virtual machines loaded with tools and documentation
  • A lab workbook comprised of over 500 pages of detailed step-by-step instructions and examples to help you master incident response and threat hunting
  • Video reviews of each lab in the workbook
  • PDFs of the course books
  • SANS DFIR Cheat Sheets to help use the tools in the field
  • A multitude of bonus labs and practice data ensure students can continue working and learning long after the course is completed

FOR508 training is an advanced incident response and threat hunting course that focuses on detecting and responding to advanced persistent threats and organized crime threat groups.The course does not cover the basics of incident response policies or digital forensics.

We recommend that you should have a background in FOR500: Windows Forensics prior to attending this course.

The FOR508 course is a part of the “Incident Response and Threat Hunting” Learning Path, with the goal of teaching skills every forensics and incident response professional should know.

Depending on your current or desired future role, one of these courses is a great next step in your cybersecurity journey:

Today’s cyber attackers use sophisticated techniques to evade detection, infiltrate networks, and persist undetected. Advanced Incident Response (IR), Threat Hunting, and Digital Forensics are essential for organizations to proactively detect, respond to, and recover from cyber incidents before they cause serious damage.

Why These Disciplines Are Crucial:

  • Threat hunting proactively identifies hidden threats that evade traditional security tools, such as fileless malware and living-off-the-land attacks.
  • Advanced IR minimizes business disruption by quickly detecting and neutralizing security breaches before they escalate.
  • Digital forensics uncovers how an attack occurred, tracing attacker movements, persistence mechanisms, and data exfiltration paths.
  • Organizations that actively hunt threats and improve response strategies can better withstand and recover from attacks.
  • Forensic investigations provide critical evidence for regulatory compliance, legal cases, and internal security audits.

When enterprises integrate these disciplines, they strengthen their cybersecurity posture, mitigate risks, and ensure rapid recovery from cyber threats, ultimately protecting sensitive data and maintaining business continuity.

Cyber threats are becoming more sophisticated, and organizations need skilled professionals who can detect, investigate, and respond to attacks effectively. FOR508: Advanced Incident Response, Threat Hunting, and Digital Forensics equips you with cutting-edge skills to stay ahead of adversaries, making you a highly valuable asset in cybersecurity.

Let’s look at how FOR508 can benefit your career:

  • Gain hands-on experience with tools like PowerShell, Velociraptor, and SIFT Workstation to hunt threats and analyze incidents.
  • Master advanced cybersecurity skills, making you a strong candidate for roles like Incident Responder, Threat Hunter, Digital Forensics Analyst, and SOC Analyst.
  • Learn how to detect hidden malware, analyze attack patterns, and track adversary movements across enterprise networks.
  • Professionals with specialized skills in IR, threat hunting, and forensics are in high demand, often commanding higher salaries.
  • Help proactively defend your organization against cyberattacks, minimizing risk and downtime.

Relevant Job Roles

Threat Hunter Training, Salary, and Career Path

Digital Forensics and Incident Response

This expert applies new threat intelligence against existing evidence to identify attackers that have slipped through real-time detection mechanisms. The practice of threat hunting requires several skill sets, including threat intelligence, system and network forensics, and investigative development processes. This role transitions incident response from a purely reactive investigative process to a proactive one, uncovering adversaries or their footprints based on developing intelligence.

Explore learning path

All-Source Collection Manager (DCWF 311)

DoD 8140: Intelligence (Cyberspace)

Identifies collection priorities, develops plans using available assets, and monitors execution to meet operational intelligence requirements.

Explore learning path

Cyber Intelligence Analyst Training, Salary, and Career Path

European Cybersecurity Skills Framework

Cyber Intelligence Analysts analyze evolving cyber threats, profile adversaries, and leverage intelligence platforms to proactively inform security decisions and mitigation strategies, bridging technical insights with strategic awareness.

Explore learning path

Digital Forensics (DGFS)

Skills Framework for the Information Age

Retrieval and interpretation of data from devices and networks to support incident response, compliance investigations, and legal cases. Work focuses on evidence integrity, validated methods, and attacker attribution.

Explore learning path

All-Source Collection Requirements Manager (DCWF 312)

DoD 8140: Intelligence (Cyberspace)

Evaluates collection strategies, develops and validates requirements, and assesses performance to optimize collection asset effectiveness.

Explore learning path

Forensics Analyst (DCWF 211)

DoD 8140: Cyber Enablers

Investigates cybercrimes, analyzing digital media and logs to establish documentary or physical evidence in support of cyber intrusion cases.

Explore learning path

Cyber Incident Responder Training, Salary, and Career Path

European Cybersecurity Skills Framework

Monitor the organisation’s cybersecurity state, handle incidents during cyber-attacks and assure the continued operations of ICT systems.

Explore learning path

Insider Threat Analysis

NICE: Protection and Defense

Responsible for identifying and assessing the capabilities and activities of cybersecurity insider threats; produces findings to help initialize and support law enforcement and counterintelligence activities and investigations.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
Showing 10 of 37

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources