Carlos Cajigas
Principal InstructorChief Technology Officer at Covert Bit
Specialities
Digital Forensics and Incident Response

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsDigital Forensics and Incident Response

Carlos Cajigas is a digital forensics and incident response (DFIR) professional with more than two decades of experience spanning both law enforcement and the private sector. A native of San Juan, Puerto Rico, he began his career with the West Palm Beach Police Department, where he advanced from patrol officer to detective, eventually specializing in computer crime investigations and digital forensics. Today, Carlos serves as Chief Technology Officer of Covert Bit Forensics and as a SANS Principal Instructor, where he teaches SANS FOR500: Windows Forensic Analysis and SANS FOR508: Advanced Incident Response, Threat Hunting, and Digital Forensics.
His teaching is grounded in investigative and technical expertise. In FOR500, Carlos draws on his background in forensic examinations and evidence handling to guide students through the collection, analysis, and interpretation of data from Windows systems. In FOR508, he applies his incident response and threat hunting experience to advanced labs on intrusion analysis, adversary tracking, and detection strategies. By blending investigative techniques with enterprise-level tradecraft, Carlos equips his students with the skills required to investigate and respond to cyber incidents across diverse environments.
Beyond his work with SANS, Carlos is an active contributor to the DFIR community. He maintains a forensic blog and a YouTube channel focused on helping practitioners adopt Linux-based open-source tools as practical complements to commercial forensic suites. On GitHub, he shares Velociraptor VQL scripts, automation for remote evidence collection with KAPE, and Python scripts for IP reputation and geolocation checks, reflecting his commitment to advancing accessible tools for investigators worldwide.
Carlos’s credentials include EnCE (EnCase Certified Examiner), CDFE (Certified Digital Forensics Examiner), CFCE (Certified Forensic Computer Examiner), GCFA (GIAC Certified Forensic Analyst), GCFE (GIAC Certified Forensic Examiner), GCIH (GIAC Certified Incident Handler), GASF (GIAC Advanced Smartphone Forensics), and GREM (GIAC Reverse Engineering Malware), and he is an FDLE-certified instructor (Florida Department of Law Enforcement). He is an active member of IACIS (International Association for Computer Information Systems) and the Miami Electronic Crimes Task Force. Through his teaching, research, and community contributions, Carlos Cajigas continues to shape the future of digital forensics and incident response.
[Carlos] showed us a few tips and tricks with the labs, which was an added bonus! Carlos is a great instructor, his ability to show other examples on the fly and switch between windows in the online environment is very impressive.
Carlos is incredibly engaging, articulate, and keeps all of the material interesting.
Carlos does an excellent job of explaining the subjects, and if we don't understand something at first, he will ensure we do.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
Investigate a real-world cyber intrusion in this hands-on digital forensics and incident response (DFIR) simulation. Trace attacker activity, analyze forensic evidence, uncover lateral movement, and reconstruct the full attack using free forensic tools.

Investiga una intrusión cibernética real en esta simulación práctica de análisis forense digital y respuesta a incidentes (DFIR). Rastrea la actividad del atacante, analiza evidencia forense, identifica movimiento lateral y reconstruye el ataque con herramientas gratuitas.

Investigate a real-world cyber intrusion in this hands-on digital forensics and incident response (DFIR) simulation. Trace attacker activity, analyze forensic evidence, uncover lateral movement, and reconstruct the full attack using free forensic tools.

Durante una presunta violacion o caza de amenazas, cuando el tiempo es esencial, interrogar y recopilar datos de un host remoto para descubrir la causa de un incidente es la prioridad numero uno. La recopilacion de datos de un host puede no ser algo nuevo, pero ?que hay de escalar esa recopilacion en cien, mil hosts o mas? Durante este webcast, analizaremos las herramientas y tecnicas que le permitiran obtener de forma rapida y eficaz la visibilidad que tanto necesita en los hosts sospechosos o que estan comprometidos. Podra utilizar estas hermientas para utilizar cualquier proceso o servicio, asi como recopilar cualquier cosa de uno o todos esos hosts de forma remota y consecutiva. Acompaneme en este webcast de una hora mientras revisamos las herramientas de respuesta a incidentes y analisis forense digital como KAPE, Kansa y Velociraptor para una clasificacion y recopilacion de datos rapida y escalable durante un incidente.
