SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsMost problems faced in Information Security are typically time sensitive. For Forensic Engineers and Analysts, it's not the problem related to when a Forensic Analyst has a local physical drive in hand; rather the problem is how quickly they can obtain forensic evidence to support or disprove data exfiltration, exploitation, or infection when the system is not locally accessible. Most times this requires remote collection and, in some cases, covert data collection. This paper will explain methods to automate collection using scripts and functions formatted mostly in PowerShell to accomplish goals. This paper will include the heavily commented version of the Yet Another Forensic Tool(YAFORTO). Where possible, prerequisites will be identified to alleviate failures already discovered during the development and testing of the scripts and functions.