The Hitchhikers Guide to Evidence Sources

  • Webcast Aired Monday, 21 Jan 2019 9:00PM EST (22 Jan 2019 02:00 UTC)
  • Speaker: Nick Klein

Note: This webcast is free of charge however a SANS portal account is required (see webcast link for details)

SANS Asia-Pacific Webcast Series- The Hitchhiker's Guide to Evidence Sources

When conducting an investigation, knowing where to find the most valuable evidence across a corporate network can be difficult. Many organisations don't consider evidence before an incident occurs, which is especially true for smaller organisations or those which don't experience incidents very often.

So in most cases, we 're limited to whatever evidence happens to be available; we collect the breadcrumbs we can find.

In this presentation, Nick will discuss the most valuable sources of evidence for several typical investigation types, so you can:

  • Identify the valuable of specific evidence sources across your environment
  • Know how forensic investigators use them to reconstruct a breach or other incident
  • Start collecting these evidence sources to maximise your ability to investigate when an incident occurs.