Heather Barnhart
FellowDFIR Curriculum Lead and Head of Faculty at SANS Institute
Specialities
Digital Forensics and Incident Response

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsDigital Forensics and Incident Response

Heather Barnhart is the DFIR Curriculum Lead and Head of Faculty at SANS Institute, where she shapes the future of digital forensics and incident response training. She is also Dean of Faculty at the SANS Technology Institute, the premier college for cybersecurity. A SANS Fellow, she is recognized for advancing smartphone forensics and Windows artifact analysis, helping investigators uncover critical evidence in today’s most complex cases.
Her career spans law enforcement, government, and industry; she previously served as Senior Director of Forensic Research at Cellebrite and now consults there as a digital forensics expert. Across nearly two decades in DFIR, Heather has worked high-profile matters, including analysis of Osama Bin Laden’s digital media and digital evidence tied to the Idaho murders case, experience that informs her practical, case-driven teaching. Her contributions have been featured in the SANS blog “Inside the Idaho Murder: How Digital and DNA Forensics Uncovered Truth”, as well as in mainstream outlets such as People and ABC 20/20. These cases, combined with her broader work in crimes against children, fraud, counterterrorism, and homicide, give her unmatched perspective in teaching practitioners how to handle real-world investigations.
At SANS, Heather leads and teaches SANS FOR585: Smartphone Forensic Analysis In-Depth and SANS FOR500: Windows Forensic Analysis, and co-authored SANS SEC403: Secrets to Successful Cybersecurity Presentation. Drawing on years of work decoding smartphone artifacts and breaking down encrypted apps, she built FOR585 to give students hands-on skills in acquiring, decoding, and interpreting iOS and Android data in real-world investigations. Her Windows expertise, ranging from registry forensics to uncovering traces in event logs, file systems, and the USN journal, directly fuels the labs and case scenarios in FOR500, preparing students to reconstruct user activity and support both incident response and criminal prosecutions.
She is co-author of the widely used book, “Practical Mobile Forensics”, a technical editor for “Learning Android Forensics” and “SQLite Forensics”, and co-author of SANS posters and white papers. A frequent keynote speaker at SANS DFIR Summits, Techno Security, and RSA Conference, where for the past seven years she has been a panelist on the keynote session “The Five Most Dangerous New Attack Techniques…and What to Do About Each”, Heather emphasizes clarity, repeatable workflows, and confidence, ensuring her students leave ready to solve the next case that lands on their desk.
OMG!!! Heather just showed me something that is going to completely change the way I do forensics.
I’ve always found SANS training to be the best training available, and this one even more so! Heather's teaching methods and the course material is phenomenal. She teaches you the why and how, not just the way to use a tool. Really great!
Heather is an outstanding instructor. She is passionate about the topic and is extremely knowledgeable. Best class I have ever taken.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
The first minutes of an incident determine containment or crisis. Join this SANS virtual roundtable to learn how leading teams align across SOC, cloud, OT, and leadership to execute faster under pressure.

As the digital landscape continues to evolve, so do the threats that put organizations at risk. With 2025 on the horizon, the urgency to anticipate and prepare for emerging cybersecurity challenges has never been greater. This webcast is designed specifically for cybersecurity practitioners who are looking to future-proof their skills and defenses to combat these challenges.

As the field of smartphone forensics evolves rapidly, the tools available often lag, particularly when it comes to processing data from third-party applications and AI-driven content.

Join us for an interactive SANS Day where cybersecurity experts and enthusiasts come together to explore the latest trends, challenges, and innovations in the field. This event promises a full day of insightful presentations, hands-on experiences, and valuable networking opportunities, and is designed for professionals at all levels. You will have the opportunity to engage with SANS Instructors and hear their insights on cybersecurity threats, customer landscape, AI, and how you can continue to development and advance in your career path. This is a must attend event for anyone passionate about staying ahead in the rapidly evolving world of cybersecurity. Don't miss out on the chance to learn, engage, connect, and grow in your cybersecurity journey!

It is no surprise that there is a shortage of cybersecurity professionals, and year upon year, these careers continue to be some of the most in-demand jobs in the corporate, healthcare, financial, education, and government sectors. While the term cybersecurity is broad in scope, there are many in-demand roles specifically in digital forensics and investigations. Digital forensics is a small subset of cybersecurity which is further broken up into many distinct disciplines, each often requiring their own set of specialized skillsets, aptitude, certifications, and on the job experience. This webcast aims to dissect some of these disciplines and get a feel from the experts why they chose their specific field and what it takes to thrive as a practitioner in niche forensic fields.Register for this webcast now and be among the first to receive the companion report by authors Domenica Crognale (SANS Certified Instructor) and Heather Mahalik (SANS Fellow).

Insider threats are some of the more difficult threats to detect from both a human and technology perspective. Understanding the problem, risks, and methods to prevent insider threats is the first step in ensuring this toxic risk does not affect your organization. Join SANS Senior Instructor Heather Mahalik, and BlackBerry VPs Pooja Kohli (Product Management), and Tony Lee (Global Services Technical Operations) to learn how insider threats and insider risk can be stopped before they begin by implementing AI-based behavior analytics software, such as BlackBerry Persona, to work alongside your defenders. Be among the first to receive the associated whitepaper written by Heather Mahalik.
