Kathryn Hedley
Certified InstructorDirector and Digital Forensic Specialist at Khyrenz Ltd.
Specialities
Digital Forensics and Incident Response

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsDigital Forensics and Incident Response

Kathryn is a Director and Digital Forensic Specialist for Khyrenz Ltd., is a SANS Instructor and has served as a forensic technical lead and Subject Matter Expert (SME) working in system assurance and evaluation, research, host-based malware intrusion investigation, forensic acquisition, and investigation for both the public and private sectors. She has led various forensic teams since 2010, spending three years embedded within a cross-organizational team, liaising directly with multiple clients.
Kathryn encourages her students to be inquisitive and learn how to make the first step in finding answers to the unknowns. Her main goal is to give students a tool-set to allow them to be productive in the office.
“I love teaching students the areas we currently understand, and paving the way for them to go away, pick up those research pieces and dig deeper into the lesser known aspects of the OS and applications. I am not one to be constrained by the live demo curse and love to break out into tools to show how things work in real life. I have always learned much more by doing than watching, and this is very much my teaching style too.” she says.
Kathryn is a Director and Digital Forensic Specialist for Khyrenz Ltd., is a SANS Instructor, and has served as a forensic technical lead and Subject Matter Expert (SME) working in system assurance and evaluation, research, host-based malware intrusion investigation, forensic acquisition, and investigation for both the public and private sectors. She has led various forensic teams since 2010, spending three years embedded within a cross-organizational team, liaising directly with multiple clients.
When Kathryn’s bachelor’s degree included a digital forensics module, she never thought it would change her career interests so drastically. “I was hooked” she says. She then managed to persuade an employer to hire her for a digital forensics role despite not having qualifications in the field. The following two years were spent pursuing her master’s degree in computer forensics and learning on the job to get up to speed.
Since then, Kathryn has served as a forensic technical lead and Subject Matter Expert (SME) working in system assurance and evaluation, research, host-based malware intrusion investigation, forensic acquisition, and investigation for both the public and private sectors. She is also a faculty member of the SANS Technology Institute, an NSA Center of Academic Excellence in Cyber Defense and multiple winner of the National Cyber League competition. Kathryn has led various forensic teams since 2010, spending three years embedded within a cross-organizational team, liaising directly with multiple clients.
“As a SME advisor on forensic issues and best practice, seizure, and acquisition in line with ACPO guidelines, I had to manage people and deliver internal forensic training for staff upskilling and knowledge dissemination. Back then, I was also in charge of research and development of new devices, tools, techniques and data sources and associated malware detection behaviors” she says.
Kathryn and SANS go way back. She attended her first SANS course in 2013 and came away utterly exhausted, but insanely exhilarated. “It was a lot of fun and taught me so much”, she says, “I managed to persuade my employer at the time to allow me to do another course through the work study program.” That gave her an amazing insight into SANS and introduced her to many amazing people, who teach, facilitate, and organize the SANS events. After that, she became a regular facilitator and considers many of those people she met very much like her extended family. Becoming an instructor was a natural progression; she wanted to work with the best training team in the world, to give students the same amazing learning experience that she had on that first course.
Kathryn is a firm believer in teaching people to fish rather than providing fish. “It doesn’t matter what your day job is. Some knowledge of digital forensics can be invaluable.” As a mentor, she wants to give back to the community and help others benefit from the lessons she has already learned on the job, the hard way. “Digital forensics is an ever-evolving field, with a never-ending stream of new things to learn. It’s one of the reasons I love it, and teaching gives me the opportunity to assist others a little way along that path, as well as meet some really cool people along the way” she says. As a teacher she encourages her students to be inquisitive and learn how to make the first step in finding answers to the unknowns. Her main goal is to give students a tool-set to allow them to be productive in the office.
Two of the challenges in digital forensics at the moment, are encryption and the increasing volume of data that needs to be analyzed. Both can add significant time to an investigation and make it extremely difficult to locate data of interest. This is the reason she as a teacher, covers step-by-step triage processes, to identify encryption and the data likely to be of most use to an investigation. She also makes sure students understand the importance of acquiring system memory, which is crucial where full disk encryption is enabled. These are standard steps in her day-to-day investigations and what she thinks are key for students to understand and use back at their jobs.
“I love teaching students the areas we currently understand, and paving the way for them to go away, pick up those research pieces and dig deeper into the lesser known aspects of the OS and applications. I am not one to be constrained by the live demo curse and love to break out into tools to show how things work in real life. I have always learned much more by doing than watching, and this is very much my teaching style too.” she says.
In her spare time Kathryn likes to write scripts and dabble in a bit of code, however, her main hobbies are sports and fitness. She has played many different sports throughout her life and grew up as a figure skater, reaching the British National Senior Squad in her late teens. She no longer skates, except maybe a little at Christmas, but still enjoys pretty much any sport and keeping fit. She also has a wish list of places she would like to travel to and explore. The list is long but she has already managed a 4-day mountain trek to Macchu Picchu, seeing the Northern Lights while cruising the Norwegian Fjords and snorkeling along the Great Barrier Reef.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
A mysterious USB stick has been found in a car park, and it’s up to you to uncover the secrets it holds. Over two nights, participants will dive into the fundamentals of digital forensics, following a step-by-step guided investigation.

A mysterious USB stick has been found in a car park, and it’s up to you to uncover the secrets it holds. Over two nights, participants will dive into the fundamentals of digital forensics, following a step-by-step guided investigation.

Those bizarre strings of letters and numbers you encounter during investigations? They might just be Base64 in disguise! This in-depth workshop is your chance to crack the code and unlock the secrets of Base64 through hands-on exercises, to learn how data – from text and images to crucial evidence – is encoded and decoded using this format.

This hands-on workshop equips you with a key skill in digital forensics: mounting and exploring forensic disk images. Uncover the secrets hidden within digital evidence!

In this workshop we'll unveil the mysteries behind how data is ordered (big or little endian) and how timestamps are stored and interpreted across different systems and applications. Through interactive exercises, you'll obtain the skills to correctly interpret data, reveal timestamps, and gain a clearer understanding of how time is represented in the digital world.

Part 3 of 6Don't believe the ‘delete’ button! This workshop equips you with the power of data recovery. We'll delve into allocated and unallocated clusters and file slack, the hidden compartments where deleted data can reside. Through hands-on exercises, you'll learn to identify different scenarios when it comes to deleted data, and recover or carve out files thought to be lost forever.

Don't be fooled by file extensions! This workshop delves deeper, equipping you to identify a file's true type using file signatures.

This hands-on series cracks the code on digital evidence. Designed for beginners, you'll unlock the secrets hidden within devices, from understanding data storage to interpreting timestamps. Learn to extract critical evidence, navigate forensic images, and convert between data formats.

Review relevant educational resources made with contribution from this instructor.