SECURITY 508SECURITY 508


GIAC Certification Available
CCE Bootcamp Logo

Course PDF

An application's activity, such as instant messaging clients that record chat conversations, USB keys installed using plug and play services, and peer-to-peer application sharing files, will potentially store data just from their installation, execution, and general use on the file system and memory. The evidence trail created by these programs could be a treasure trove of crucial data that might make or break your case. You will learn how to utilize advanced analysis techniques, called Application Footprinting, to discover where you might find and uncover crucial evidence that was created or stored from the application being installed or executed on your suspect system.

For the majority of the day you will employ the techniques learned throughout the week in a systematic hands-on intrusion investigation case. You will analyze a real-world compromised system where you might be able to discover who the suspect is online via the investigative methodology we have utilized in the course.




  • Application Footprinting and Software Forensics
    • What Application Footprinting Is And How It Is Useful In An Investigation
    • Utilize Both File And Configuration Residue From Applications Can Be Examined Using Timeline Analysis
    • Perform Registry Analysis Of Applications And Artifacts
    • Utilize Both File And Configuration Residue From Applications Can Be Examined Using Memory Analysis
  • The Forensic Challenge
    • Real-World Compromise To Investigate From Beginning To End
    • Exercise Your Forensic Skills
    • Perform Difficult Forensic Tasks With Ease Using Autopsy
    • Timeline Creation
    • String Searches
    • Unallocated Space Analysis
    • Data Recovery And Analysis
  • Day 6 Exercises
    • Forensic Challenge (Choose Either a Compromised Windows or a Unix Machine to Analyze)
SECURITY 508 Upcoming Events
Event Location Dates Delivery Method
SANS SelfStudyBooks & MP3s OnlyAnytimeSelf Paced
SANS OnDemandOnlineAnytimeSelf Paced
SANS London 2009London, United KingdomNov 28, 2009 - Dec 06, 2009Live Event
Community SANS Tucson 2009Tucson, AZNov 30, 2009 - Dec 05, 2009Community SANS
Community SANS Colorado Springs 2009Colorado Springs, CONov 30, 2009 - Dec 05, 2009Community SANS
Mentor Session - SEC508Atlanta, GADec 02, 2009 - Feb 17, 2010Mentor
Mentor Session - SEC508Medellín, ColombiaDec 02, 2009 - Dec 04, 2009Mentor
SANS CDI East 2009Washington DCDec 11, 2009 - Dec 18, 2009Live Event
Mentor Session - Security 508Charlotte, NCJan 14, 2010 - Mar 18, 2010Mentor
Mentor Session - Security 508Denver, COJan 19, 2010 - Mar 23, 2010Mentor
Community SANS Lake Tahoe 2010Lake Tahoe, CAJan 25, 2010 - Jan 30, 2010Community SANS
SANS Phoenix 2010Phoenix, AZFeb 14, 2010 - Feb 20, 2010Live Event
SANS India 2010Bangalore, IndiaFeb 22, 2010 - Feb 27, 2010Live Event
SANS 2010Orlando, FLMar 06, 2010 - Mar 15, 2010Live Event
Mentor Session - SEC508Greeley, COMar 11, 2010 - May 13, 2010Mentor
Community SANS Boston 2010Boston, MAMar 15, 2010 - Mar 20, 2010Community SANS
SANS vLive! - SEC 508 - Rob LeeSANS vLive! SEC508 - 201003, VAMar 23, 2010 - Apr 29, 2010
SANS Northern Virginia Bootcamp 2010Reston, VAApr 06, 2010 - Apr 13, 2010Live Event
Mentor Session - SEC508Boise, IDSep 28, 2010 - Nov 30, 2010Mentor
"This is awsome! We're seeing details that most people don't even know exist" - John Wright, Info Tech, Inc.
"The class provided in-depth, real world, hands-on information" - Robert Dale Drollinger, General Dynamics
SANS Institute