Group Purchasing
Group Purchasing

FOR589: Cybercrime Investigations

FOR589Digital Forensics and Incident Response
  • 5 Days (Instructor-Led)
  • 30 Hours (Self-Paced)
Course authored by:
Conan BeachSean O'ConnorWill Thomas
Conan Beach, Sean O'Connor & Will Thomas
FOR589: Cybercrime Intelligence
Course authored by:
Conan BeachSean O'ConnorWill Thomas
Conan Beach, Sean O'Connor & Will Thomas
  • 30 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Intermediate Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 20 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Learn how to investigate cybercrime from end to end — uncover attacker tactics, trace financial activity, and analyze digital evidence to support attribution and incident response.

Course Overview

Today’s dynamic cybercrime ecosystem continuously lowers the barriers for novice criminals to collaborate with more sophisticated actors. FOR589 Cybercrime Investigations offers a comprehensive exploration of the cybercrime underground, detailing a broad spectrum of tactics and techniques used by cybercriminals to target organizations. This cybercrime training course includes over twenty hands-on labs and a final capstone exercise, equipping analysts with the skills necessary to enhance their organization's defenses, proactively gather critical intelligence, trace cryptocurrency proceeds linked to crime, and generate actionable insights.

Track, Trace, Disrupt: Master the Art of Cybercrime Investigations

There are ways to stay ahead of cybercrime and extend your perimeter. It starts with knowing the vast landscape you are up against and applying investigative methodologies to uncover and disrupt criminal operations.

Cybercrime investigations are essential for organizations aiming to detect, respond to, and attribute malicious activity, as well as for law enforcement and government agencies working to identify, arrest, and prosecute cybercriminals. FOR589: Cybercrime Investigations provides a deep dive into the global cybercrime underground, revealing the tactics and techniques threat actors use to exploit systems and monetize attacks. This course blends investigative tradecraft with modern cybersecurity practices to enhance operations. Whether you're part of a corporate security team, a government investigator, or simply looking to build your skills in tracking and understanding organized cybercrime and threats to your organization, this course will elevate your capabilities.

FOR589: Cybercrime Investigations will teach you how to map infrastructure, analyze threat actor capabilities, and identify victims, while working toward attribution of real-world criminal activity. Students will explore criminal underground forums, trace cryptocurrency transactions, and dissect laundering schemes used by cybercriminals. The course emphasizes safe online investigative practices, including creating sock puppets, engaging with threat actors, and infiltrating underground communities. Through hands-on labs and real-world case studies, participants will investigate cyber threats, collect and analyze digital evidence, and uncover the scope, scale, and impact of cybercriminal campaigns—aligning all findings with strategic intelligence priorities.

FOR589 Cybercrime Investigations Course Topics:

  • Online investigative fundamentals and applying traditional cyber frameworks to cybercrime
  • Navigate underground communities and understand the criminal ecosystem
  • Conduct covert online investigations to gain placement and access for case development
  • Using platforms to pivot, track, and monitor targets in support of investigations
  • Structuring digital evidence collection in line with intelligence requirements and legal standards
  • Managing cybercrime research at the strategic, operational, and tactical levels
  • Attribution of people, money, and infrastructure using investigative methodologies
  • Leveraging the Diamond Model and MITRE ATT&CK for investigative analysis
  • Supporting incident response using external datasets that reach beyond the network perimeter.
  • Mapping adversarial relationships and identifying criminal targeting patterns
  • Understanding pseudonymity and anonymity in the context of operational security
  • Conducting social engineering operations to elicit key information from cybercriminals
  • Tracing cryptocurrency transactions to connect payments to illicit entities
  • Uncovering money laundering techniques involving mixers and cross-chain activity

Author Statement

"Cybercrime isn’t just a threat—it’s the threat redefining the modern battlefield for security professionals. In FOR589: Cybercrime Investigations, we train defenders to get left of boom—to investigate, infiltrate, and dismantle criminal networks before they strike. As financially motivated attacks surge, so does the need for those who can uncover the actors, follow the money, and build intelligence that leads to action. This course teaches students to trace illicit activity across forums, blockchains, and underground economies—equipping them with the knowledge and foresight to outsmart attackers and stop threats before they happen. FOR589 is where intelligence meets action—break the criminal cycle and reduce the blast radius."

- Sean O'Connor

"More organizations need to realize that cybercrime is the number one threat to their organization's IT operations. Illicit fortunes amassed by organized cybercrime groups have led to an emboldened underground economy that currently revolves around ransomware. This is because ransomware attacks persist as one of the most profitable and destructive methods of monetizing access to any type of network. The Colonial Pipeline ransomware incident in 2021 was the most disruptive cyberattack on U.S. critical infrastructure to date, which showcased that unabated cybercrime directly leads to real-world catastrophes. It is thus more important than ever to understand the core drivers behind this threat. SANS FOR589 will arm students with the knowledge to investigate sources of cybercrime, track cybercriminals financially, infiltrate underground communities, and, ultimately, disrupt the adversaries."

- Will Thomas

"Cybercriminals frequently penetrate networks with the primary goal of financial gain. Unfortunately, many organizations leave their sensitive data and intellectual property vulnerable to theft and exploitation, which leaves them with few options when they fall victim to a ransomware attack. They will often pay these ransoms, fueling the financial capabilities of these adversaries and escalating the threat of subsequent breaches. In FOR589, we equip students with the skills to delve into the depths of the cybercrime underworld. This exploration is key to comprehending the motives and proficiencies of cyber adversaries, which is essential for bolstering an organization's defenses and mitigating the likelihood of future security incidents, hopefully breaking this vicious cycle. In FOR589 we will teach students how to safely explore this criminal ecosystem and also provide practical training for tracing cryptocurrency transactions, offering even more intelligence by monitoring financial flows across blockchains."

- Conan Beach

What You’ll Learn

  • Adapt traditional investigative methods to the cyber domain and uncover risks specific to your organization
  • Investigate dark web marketplaces, forums, and threat actor communications
  • Separate actionable leads from background noise to drive informed, evidence-based decisions
  • Translate investigative goals into structured collection and case development plans
  • Build and manage covert personas to safely access underground communities and collect evidence
  • Trace cryptocurrency transactions to uncover threat actors, affiliates, and laundering
  • Vet sources and communities for credibility and access to support investigative objectives

Business Takeaways

  • Bridge cybercrime and crypto crime knowledge gaps across investigative teams
  • Enhance fraud, incident response, and CTI capabilities with specialized cybercrime expertise
  • Detect and investigate emerging threats and actors before attacks escalate
  • Build proactive alerts and detection based on criminal behavior and underground trends
  • Track threat actors through malware, access, affiliate activity, and crypto/infrastructure analysis
  • Deliver tailored, actionable insights to support strategic decisions and improve attribution

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in FOR589: Cybercrime Intelligence.

Section 1Cybercriminal Intelligence

This section covers the intelligence lifecycle in cybercrime investigations, emphasizing structured methods for threat profiling, persona management, and secure data collection from underground sources. Students will learn to turn fragmented data into actionable intelligence to support investigations and strategic decisions.

Topics covered

  • Intelligence basics & structured analysis
  • Collection planning for cybercrime
  • Cyberattack profiling frameworks
  • OPSEC & defense-in-depth
  • Persona & sock puppet management

Labs

  • Set up VM & test OPSEC
  • Track actors via breach data
  • Manage long-term sock puppets
  • Link analysis with Maltego
  • Create secure crypto wallets

Overview

Section one provides the critical foundation for conducting secure, ethical, and effective cybercrime investigations. Students are introduced to the cybercrime intelligence cycle, where they learn to define Priority Intelligence Requirements (PIRs), build defensible collection plans, and assess risk before taking investigative action.

You'll explore what separates information from intelligence, how to turn raw data into finished intel (FINTEL), and how to apply frameworks to cybercrime campaign analysis. The section also covers how to evaluate vendor intelligence platforms, interpret breach data, and structure digital dossiers on adversaries.

A significant focus is placed on operational security (OPSEC). Students will model their own digital tradecraft to avoid becoming the investigated while investigating—covering VPN usage, browser fingerprinting, network obfuscation, persona design, and sock puppet creation. Real-world OPSEC failures, including case studies from AlphaBay and Fractal ID, are analyzed to reinforce lessons learned.

Hands-on labs walk students through configuring their investigative workstations, building online personas, performing password pivoting using breach data, and analyzing social and infrastructure links with Maltego. Students also create a cryptocurrency wallet to support future controlled buys or underground engagement, laying the groundwork for the capstone exercise in Section 5.

This section ensures students are not only collecting intelligence safely, but doing so with structure, legality, and purpose—ready to support their organization or agency in high-stakes environments.

Full Topic Details

  • Intelligence Fundamentals & Structured Analysis
  • Collection Planning & Cybercrime Requirements
  • Cyberattack Profiling using Industry Frameworks
  • Operational Security: Defense-in-Depth Modeling
  • Persona Development & Sock Puppet Management
  • Tools for Attribution: Password Pivots, Wallet Analysis, and Forums

Full Lab Details

  • Configure your investigative VM and test OPSEC tooling
  • Use breached data and password pivoting to track actors
  • Safely create and maintain long-term sock puppet accounts
  • Perform visual link analysis with Maltego and digital dossiers
  • Create and secure a cryptocurrency wallet for underground use

Section 2Cryptocurrency Investigations

This section teaches students to trace illicit cryptocurrency activity using blockchain analytics and attribution techniques. Through real-world case studies, students will learn to follow laundering tactics, cluster wallets, and use OSINT and off-chain data to link transactions to threat actors, aiding in investigations and asset recovery.

Topics covered

  • Blockchain tracing fundamentals
  • UTXO vs. account models
  • Wallet clustering and heuristics
  • Obfuscation: mixers, CoinJoins, hopping
  • Attribution via OSINT and KYC

Labs

  • Study Genesis Block and UTXO
  • Analyze Twitter crypto scam wallets
  • Trace bulletproof host crypto flows
  • Follow Bitfinex laundering patterns
  • Track Colonial Pipeline ransom trail

Overview

Section two dives deep into the blockchain-backed financial systems cybercriminals rely on to move, launder, and obscure illicit gains. Students will learn to map and decode cryptocurrency transactions, identify laundering patterns, and attribute wallets to real-world threat actors through a combination of on-chain and off-chain analysis.

Beginning with blockchain fundamentals, students will understand both the UTXO-based model (Bitcoin) and account-based model (Ethereum), enabling precise transaction analysis. Using heuristics such as round numbers, input/output patterns, and known entity clustering, students will perform wallet clustering and change analysis to trace funds through complex laundering schemes. These techniques are especially critical in ransomware and infostealer investigations, where tracing payments may lead to actor attribution or even asset recovery.

The section also introduces students to mixers, CoinJoins, chain hopping, and peel chains, exploring how criminals attempt to obscure transactions—and how investigators can still track them. Case studies from the Bitfinex hack, DarkSide ransomware, and scam campaigns will help bring these concepts into practical focus.

Students will utilize tools like Chainalysis Reactor for advanced clustering and exposure analysis, while learning how to enrich on-chain data with KYC records, sanctions designations, and OSINT. A strong emphasis is placed on turning blockchain data into FININT—financial intelligence that can inform incident response, strategic decisions, and legal action.

Each lab offers hands-on, realistic practice in tracing cybercriminal transactions, profiling laundering behavior, and uncovering infrastructure linked to criminal organizations. By the end of this section, students will be equipped to follow illicit cryptocurrency flows with confidence, support attribution, and assist in dismantling financially-motivated cybercrime operations.

Full Topic Details

  • Fundamentals of blockchain and cryptocurrency tracing
  • UTXO and account-based models (Bitcoin, Ethereum)
  • Wallet clustering, change analysis, and transaction heuristics
  • Tracing obfuscation methods: mixers, CoinJoins, chain hopping, peel chains
  • Attribution using OSINT, KYC, sanctions data, and wallet fingerprinting
  • Analysis of laundering tactics in real-world ransomware and cybercrime campaigns
  • Blockchain FININT: Turning transaction data into strategic and tactical intelligence

Full Lab Details

  • Explore the Bitcoin Genesis Block and foundational transaction models (UTXO)
  • Analyze high-profile Twitter crypto scams using heuristics and wallet fingerprinting
  • Profile bulletproof hosting providers by tracing their cryptocurrency activity
  • Follow laundering techniques from the Bitfinex hack using advanced blockchain analysis
  • Track the Colonial Pipeline ransomware payment and investigate the DarkSide affiliate

Section 3Cybercrime Underground

In this section, students learn how to safely navigate and investigate cybercriminal communities across surface, deep, and dark web environments. Uncover how forums, leak sites, messaging platforms, and infrastructure tie together into a functional underground economy—and how adversaries interact to buy, sell, and monetize access, data, and capabilities.

Topics covered

  • Profile forums, markets, and apps
  • Understand cybercriminal roles and groups
  • Investigate infrastructure via profiling
  • Identify victims across sources
  • Map threats with ATT&CK, Diamond

Labs

  • Identify forums, markets, leak sites
  • Pivot on infrastructure with OSINT
  • Build actor dossiers from forums
  • Map tools with ATT&CK and OSINT
  • Investigate real ransomware campaigns

Overview

Section three takes students deep into the operational environments where cybercriminals collaborate, transact, and conduct business. You’ll learn to safely explore and investigate forums, marketplaces, extortion sites, encrypted messaging apps, and infrastructure nodes used by actors to buy and sell access, malware, credentials, and illicit services.

This section teaches you how to profile underground communities, understand forum structures, identify moderators, and spot overlaps between actors and platforms. You'll explore how ransomware groups recruit affiliates, how initial access brokers monetize network access, and how infostealer logs and marketplace transactions expose both threat actors and victims.

Students will investigate how cybercriminals host infrastructure—using services like bulletproof VPS providers, registrars, and mixers—and trace their financial and technical footprints. You’ll use tools like Shodan, URLscan, and Maltego to pivot from domains and IPs, build attacker infrastructure profiles, and correlate IOCs with campaign data from public and commercial platforms.

By building digital dossiers on threat actors, students will learn how to identify usernames, cryptocurrency wallets, and behavioral patterns that form a unique signature across forums, markets, and leak sites. You’ll also study adversary social networks and identify trusted relationships, vouching behavior, and reputation systems used by underground actors.

Ransomware victimology is a key focus, with students tracing victim data across extortion blogs, infostealer logs, and credential markets. Frameworks like MITRE ATT&CK and the Diamond Model are used to help students categorize, assess, and predict adversary behavior and campaign evolution.

By the end of this section, students will be equipped to map the criminal economy, track adversaries over time, and analyze infrastructure and victim data with precision—skills critical for any cybercrime investigator or intelligence analyst.

Full Topic Details

  • Profiling forums, marketplaces, ransomware leak sites, and messaging apps
  • Understanding the roles of initial access brokers, ransomware affiliates, malware developers, and cybercrime forum members
  • Investigating cybercrime infrastructure using profiling techniques
  • Identifying victims across markets, extortion sites, and infostealer logs
  • Mapping capabilities using frameworks like MITRE ATT&CK and the Diamond Model
  • Uncovering identifiers (usernames, passwords, emails, wallets) and behavioral patterns
  • Profiling malware, phishing, and exploit services offered in the underground
  • Investigating and mapping ransomware victimology and campaign activity
  • Understanding adversary tradecraft, criminal ecosystems, and infrastructure reuse

Full Lab Details

  • Identify and enumerate cybercrime forums, marketplaces, and leak sites
  • Investigate and pivot off adversary infrastructure using OSINT tools
  • Profile an underground actor by building a digital dossier from forum activity
  • Map capabilities and malware services using ATT&CK and open-source intelligence
  • Investigate ransomware campaigns, victims, and exposure through real-world cases

Section 4Undercover Operations

In this section, students will learn how to infiltrate gated criminal communities, build credible personas, and collect human intelligence (HUMINT) directly from threat actors. You’ll explore both manual and automated approaches to collecting data, from eliciting adversaries through social engineering to scraping dark web content at scale.

Topics covered

  • HUMINT: spot, assess, profile
  • Social engineering in investigations
  • Automate dark web scraping
  • Analyze trends with Kibana
  • Attribute and disrupt threat actor

Labs

  • Create sock puppet for access
  • Map forum rules, key actors
  • Scrape via Tor, analyze in Kibana
  • Profile actors with targeting frameworks
  • Use HUMINT to assess adversaries

Overview

Section four provides students with the skills to safely and strategically enter the cybercriminal underground, establish a trusted presence, and collect intelligence directly from adversaries. From building long-term sock puppets to deploying automated scrapers, this section blends human and technical collection tradecraft to deliver real investigative value.

Students will begin with operational planning and OPSEC, learning how to manage attribution risks and comply with legal boundaries. You’ll explore how cybercriminal forums and marketplaces operate—what it takes to gain access, how to engage safely, and how to identify gatekeeping mechanisms like invite-only referrals, entry fees, and application processes.

Once inside, students will learn to blend in, engage, and extract. HUMINT tradecraft is introduced with emphasis on elicitation tactics, engagement strategies, and persona development. Students will practice spotting and assessing sources, evaluating their placement, access, reliability, and behavioral cues using frameworks like the Admiralty Code and MITRE Engage.

In tandem with human collection, students will explore the use of web scrapers to automate dark web data collection, analyzing patterns in ransomware operations, access sales, and criminal services. Using Kibana, students will visualize cybercrime datasets, pivot on keywords and actor names, and generate actionable dashboards to support attribution or countermeasures.

The section culminates with mapping HUMINT collections to strategic outcomes—whether it's exposing infrastructure, enabling law enforcement takedowns, or preempting ransomware deployments. By bridging technical automation with human engagement, students gain a comprehensive toolkit for infiltrating, investigating, and influencing the underground.

Full Topic Details

  • Persona creation and maintaining access in cybercriminal communities
  • Navigating underground forums, marketplaces, and encrypted chats
  • HUMINT collection: spotting, assessing, targeting, and profiling sources
  • Social engineering and elicitation tradecraft in cybercrime investigations
  • Automating dark web data collection using scrapers and evasion tactics
  • Visualizing and analyzing cybercrime trends in Kibana
  • Attribution and disruption strategies for threat actors and infrastructure

Full Lab Details

  • Create and operationalize a sock puppet persona to access closed forums
  • Map forum access requirements and identify influential threat actors
  • Build and deploy a Tor-based scraper; analyze data in Kibana dashboards
  • Profile cybercriminals using structured targeting frameworks
  • Apply HUMINT tradecraft to elicit adversary insights and assess credibility

Section 5Capstone Exercise

The final day of FOR589 is a capstone challenge that focuses on launching an investigation. Students engage in a fun and meaningful exercise that brings together various components of the entire course. The capstone will reinforce the principles taught via a simulated scenario that enables students to practice implementing their newly learned skills.

Overview

Students will be presented with a simulated investigation involving a fully interactive cybercrime forum. They will have to analyze posts and profiles from the forums, as well as leaked private chat logs and seized databases. There will also be a fictional blockchain ledger that students will use to trace transactions and track threat actors and various types of activities. Students will have to think about how to fulfil intelligence requirements of law enforcement and through a supporting CTI perspective, using the data sets provided that emulate real-world scenarios. Students will be placed in teams and will need to present their findings on what their investigation uncovered, including the steps taken, what they collected, processed, analyzed, and how it can be exploited.

Things You Need To Know

Important! Bring your own system configured according to these instructions. 

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all the specified requirements. 

Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data. 

Mandatory System Hardware Requirements 

  • CPU: A 64-bit system processor and operating system are mandatory, Intel i5/i7 (8th gen+) or AMD Ryzen 5/7 or more recent. 
  • CRITICAL NOTE: Apple Silicon devices (starting with M1 processors) cannot perform the necessary virtualization and therefore cannot in any way be used for this course. 
  • BIOS settings must be set to enable virtualization technology, such as "Intel-VT." 
  • Be certain that you can access your BIOS if it is password-protected in case changes are necessary. Test it! 
  • 16 gigabytes (GB) of RAM or higher is mandatory for this class. 
  • USB 3.0 Type-A port is required or a Type-C to Type-A adapter may be necessary for newer laptops. At least one open and working USB 3.0 port is required. (Note: Some endpoint protection software prevents the use of USB devices, so test your system with a commercial USB drive before class to ensure that you can load the course data.) 
  • 100 GB of free space on your system hard drive is critical to host the VMs we distribute. 
  • Local administrator access is absolutely required. Do not let your IT team tell you otherwise. If your company will not permit this access for the duration of the course, then you should make arrangements to bring a different laptop. 
  • Wireless 802.11 capability 

Mandatory Host Configuration and Software Requirements 

  • Your host operating system must be the latest version of Windows, or macOS 13 or newer. 
  • Fully update your host operating system prior to the class to ensure you have the right drivers and patches installed. 
  • Linux hosts are not supported in the classroom due to their numerous variations. If you choose to use Linux as your host, you are solely responsible for configuring it to work with the course materials and/or VMs. Please note: It is necessary to fully update your host operating system prior to the class to ensure that you have the right drivers and patches installed. 
  • Those who use a Linux host must also be able to access ExFAT partitions using the appropriate kernel or FUSE modules. 
  • You should ensure that antivirus or endpoint protection software is disabled, fully removed, or that you have the administrative privileges to do so. Many of our courses require full administrative access to the operating system and these products can prevent you from completing the labs. 
  • Any filtering of egress traffic may prevent accomplishing the labs in your course. Firewalls should be disabled, or you must have the administrative privileges to disable it. 

Please Install the Following Software Prior to Class 

  • Download and install VMware Workstation Pro 17+ (for Windows hosts), or VMWare Fusion Pro 13+ (for macOS hosts) prior to class beginning. Workstation Pro and Fusion Pro are now available free for personal use from the VMware website. Licensed commercial subscriptions to these products can also be used. Download links for these products will be provided in your SANS Account Dashboard after registering for the course. 
  • On Windows hosts, VMware products might not coexist with the Hyper-V hypervisor. For the best experience, ensure VMware can boot a virtual machine. This may require disabling Hyper-V. Instructions for disabling Hyper-V, Device Guard, and Credential Guard are contained in the setup documentation that accompanies your course materials. 
  • Download and install 7Zip (for Windows Hosts) or Keka (macOS). These may be included in your SANS courseware .ISO files. 

Your course media is delivered via download from the SANS "Course Material Downloads" page in your SANS account. The media files for the class can be large, some in the 40 to 50 GB range. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as soon as you get the link. You will need your course media immediately on the first day of class. Waiting until the night before the class starts to begin your download has a high probability of failure. 

SANS has begun providing printed materials in PDF form. Additionally, certain classes are using an electronic workbook in addition to PDFs. The number of classes using eWorkbooks will grow quickly. Considering this, we have found that a second monitor and/or a tablet device can be useful to keep the class materials visible while the instructor is presenting or while you are working on lab exercises. 

If you have additional questions about the laptop specifications, please contact customer service. 

FOR589 training is recommended for a diverse range of individuals, including:

  • Cyber Threat Intelligence Analysts who want to refine their grasp of the threat intelligence lifecycle's relevance to practical cybercrime activities. The course is particularly useful for analysts tasked with researching and monitoring threat leads.
  • Cyber Intelligence Professionals who aim to enhance their comprehension of the cybercrime landscape, broaden their familiarity with criminal tactics, evaluate and monitor underground sources, and develop their ability to infiltrate and collect information from such sources.
  • Criminal Actor Investigators who want to hone their skills in collecting, analyzing, and leveraging cybercrime intelligence, and increase their effectiveness in solving cybercrime cases and holding cybercriminals accountable for their actions.
  • Financial Crime Investigators who aim to bridge the knowledge gap between cryptocurrency crimes and the underground cybercriminal ecosystem upon which financial crimes are built in order to ensure that more investigative sources are accounted for.
  • Threat Hunters who seek to improve their proactive threat-hunting capabilities, learn how to identify and track cybercriminals, and understand how to apply cybercrime intelligence to generate and prioritize threat leads and hunt hypotheses.
  • Incident Responders who want to enhance their ability to respond to and manage cybercrime incidents, learn best practices in evidence preservation, and streamline collaboration with other stakeholders during investigations.
  • Forensic Analysts who want to deepen their knowledge of digital forensics in the context of cybercrime, learn how to extract and analyze relevant data from underground sources, and adapt their methodologies to address emerging threats.
  • Information Security Professionals who aim to broaden their understanding of the cybercrime landscape, stay informed about threats emerging from the underground, and develop plans to counter criminal methods used in cyberattacks and cyber fraud.
  • Federal Agents and Law Enforcement Professionals who need to stay current with the latest trends in cybercrime, improve their investigative skills, and better understand and collaborate with partners in the public and private sectors to combat cybercrime.
  • SANS Alumni looking to take their skills to the next level.

  • A custom virtual machine preloaded with investigation tools for use during and after class
  • Demo access to Authentic8 Silo for safe dark web and surface web investigations.
  • Demo access to Chainalysis Reactor, enabling hands-on cryptocurrency tracing and blockchain analysis
  • Demo access to Maltego, allowing you to visualize relationships between threat actors, infrastructure, and digital footprints using link analysis

FOR589: Cybercrime Investigations is a course focused on navigating, discovering, detecting, and disrupting threats from the cybercrime economy. First-time SANS students will be successful in this course as the technical demands of this course are on par with those of other beginner SANS courses.

Students may benefit from having taken one of the SANS courses listed below, or equivalent training. However, while these courses are helpful, they are not required.

The FOR589 course is part of the Digital Forensics, Malware Analysis, & Threat Intelligence Learning Path, designed to impart the specialized investigative skills you will need to perform forensics, threat intelligence, and malware analysis.

Other courses that are part of this Focus Area and Learning Path include:

Cybercrime investigation helps organizations anticipate, prevent, and mitigate future cyber threats while aiding law enforcement in investigating and prosecuting cybercriminals. Cybercrime investigation is key to helping organizations:

  • Proactively identify and address looming threats before attacks occur
  • Make informed decisions about resource allocation based on real-time threat information
  • Support law enforcement with evidence and insights to aid investigations

The FOR589 course equips you with the skills you need to anticipate, prevent, and mitigate potential cyber threats within your organization. Develop an in-depth understanding of the cybercrime underground while expanding knowledge of traditional intelligence and contemporary cybersecurity. Gain hands-on experience with cybersecurity tools and work on real-life case studies, helping you thwart potential threats before they escalate.

Relevant Job Roles

Cyber Intelligence Analyst Training, Salary, and Career Path

European Cybersecurity Skills Framework

Cyber Intelligence Analysts analyze evolving cyber threats, profile adversaries, and leverage intelligence platforms to proactively inform security decisions and mitigation strategies, bridging technical insights with strategic awareness.

Explore learning path

Insider Threat Analysis

NICE: Protection and Defense

Responsible for identifying and assessing the capabilities and activities of cybersecurity insider threats; produces findings to help initialize and support law enforcement and counterintelligence activities and investigations.

Explore learning path

Threat Management

SCyWF: Protection And Defense

This role collects and analyzes information about threats, searches for undetected threats and provides actionable insights to support cybersecurity decision-making. Find the SANS courses that map to the Threat Management SCyWF Work Role.

Explore learning path

Cybercrime Investigation (CRIM)

Skills Framework for the Information Age

Collection, preservation, and analysis of digital evidence to trace cybercrime and support prosecution efforts. Technical artefacts are translated into admissible findings in collaboration with legal and law enforcement teams.

Explore learning path

Digital Forensics (OPM 212)

NICE: Protection and Defense

Responsible for analyzing digital evidence from computer security incidents to derive useful information in support of system and network vulnerability mitigation.

Explore learning path

Media Exploitation Analyst

Digital Forensics and Incident Response

This expert applies digital forensic skills to a plethora of media that encompasses an investigation. If investigating computer crime excites you, and you want to make a career of recovering file systems that have been hacked, damaged or used in a crime, this may be the path for you. In this position, you will assist in the forensic examinations of computers and media from a variety of sources, in view of developing forensically sound evidence.

Explore learning path

Threat Intelligence (THIN)

Skills Framework for the Information Age

Collection and contextual analysis of threat actor activity, indicators, and tactics. Outputs support detection engineering, hunting strategies, and proactive defence planning.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
  • Location & instructor

    Virtual (OnDemand)

    Instructed by
    Date & Time
    OnDemand (Anytime)Self-Paced, 4 months access
    Course price
    $8,260 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS August Singapore 2026

    Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    S$10,720 SGD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS London October 2026

    London, GB & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    £6,715 GBP*Prices exclude applicable taxes | EUR price available during checkout
    Registration Options
  • Location & instructor

    SANS DFIR Summit & Training 2026

    Arlington, VA, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,260 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Cyber Safari 2026

    Riyadh, SA & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,375 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Paris November 2026

    Paris, FR

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    €7,715 EUR*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Cyber Defense Initiative 2026

    Washington, DC, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,260 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Baltimore 2027

    Baltimore, MD, US & Virtual (live)

    Date & Time
    Fetching schedule..
    Course price
    $8,260 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANSFIRE 2027

    Washington, DC, US & Virtual (live)

    Date & Time
    Fetching schedule..
    Course price
    $8,260 USD*Prices exclude applicable local taxes
    Registration Options
Showing 9 of 9

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources