Computer Forensic Investigators should be conversant with network and file system forensics in addition to being armed with the latest in incident response tools and methodologies. The day starts with learning how to acquire system memory, volatile data, and the hard drive as evidence from a compromised machine. You will learn how to acquire evidence across a network, from a live machine, and even from a hard drive that is sent to you for examination. The latter part of the day will focus on file system timeline analysis where you will be able to track the intruder through the file system by examining file system time stamps.
You will analyze live machines that will put you personally in charge of investigating an incident. Part of the courseware DVD includes a compromised VMware machine that was suspended immediately after being hacked remotely for you to test your incident response and evidence collection skills. You will learn how to minimize damage to the evidence of the live machine while learning how to acquire volatile evidence from the machine. Finally, you will learn how to image a hard drive as evidence and maintain evidence integrity through a variety of methods using the SIFT kit.
You are encouraged to bring a used hard drive from your organization or from home to practice on during the evidence acquisition section, but this is not required. The instructor will demonstrate the skills discussed in the course and the manuals will include numerous screen shots.
| SECURITY 508 Upcoming Events | |||
| Event | Location | Dates | Delivery Method |
| SANS SelfStudy | Books & MP3s Only | Anytime | Self Paced |
| SANS OnDemand | Online | Anytime | Self Paced |
| SANS London 2009 | London, United Kingdom | Nov 28, 2009 - Dec 06, 2009 | Live Event |
| Community SANS Tucson 2009 | Tucson, AZ | Nov 30, 2009 - Dec 05, 2009 | Community SANS |
| Community SANS Colorado Springs 2009 | Colorado Springs, CO | Nov 30, 2009 - Dec 05, 2009 | Community SANS |
| Mentor Session - SEC508 | Atlanta, GA | Dec 02, 2009 - Feb 17, 2010 | Mentor |
| Mentor Session - SEC508 | Medellín, Colombia | Dec 02, 2009 - Dec 04, 2009 | Mentor |
| SANS CDI East 2009 | Washington DC | Dec 11, 2009 - Dec 18, 2009 | Live Event |
| Mentor Session - Security 508 | Charlotte, NC | Jan 14, 2010 - Mar 18, 2010 | Mentor |
| Mentor Session - Security 508 | Denver, CO | Jan 19, 2010 - Mar 23, 2010 | Mentor |
| Community SANS Lake Tahoe 2010 | Lake Tahoe, CA | Jan 25, 2010 - Jan 30, 2010 | Community SANS |
| SANS Phoenix 2010 | Phoenix, AZ | Feb 14, 2010 - Feb 20, 2010 | Live Event |
| SANS India 2010 | Bangalore, India | Feb 22, 2010 - Feb 27, 2010 | Live Event |
| SANS 2010 | Orlando, FL | Mar 06, 2010 - Mar 15, 2010 | Live Event |
| Mentor Session - SEC508 | Greeley, CO | Mar 11, 2010 - May 13, 2010 | Mentor |
| Community SANS Boston 2010 | Boston, MA | Mar 15, 2010 - Mar 20, 2010 | Community SANS |
| SANS vLive! - SEC 508 - Rob Lee | SANS vLive! SEC508 - 201003, VA | Mar 23, 2010 - Apr 29, 2010 | |
| SANS Northern Virginia Bootcamp 2010 | Reston, VA | Apr 06, 2010 - Apr 13, 2010 | Live Event |
| Mentor Session - SEC508 | Boise, ID | Sep 28, 2010 - Nov 30, 2010 | Mentor |