SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsThe purpose of this paper is to be an introduction to computer forensics. Computer forensics is a newly emerged and developing field which can be described as the study of digital evidence resulting from an incident. It involves collection and analysis of digital data within an investigative process. Other important steps include incident preparation, detection and recovery. All these procedures should be documented and conducted according to a standard methodology (Mandia and Prosise, 2001; McMillan, 2000). After introducing some important incident response considerations I will focus on a strategies for dealing with compromised Windows NT/2000. My hope is that this paper might be of some assistance in handling your own incidents and investigations. This paper is about investigating Windows hosts and conducting an analysis in order to promote growth and learning as opposed to a 'how-to' guide to gather legal evidence in view of criminal prosecution.