Included in your paid tuition, you will receive the SANS Investigative Forensic Toolkit (SIFT) Advanced. Using the hardware and software in this toolkit, you will gain first-hand experience in collecting and analyzing evidence recovered from a system under investigation. You will learn best practices on how to investigate and recover deleted data. The course will demonstrate how forensic tools recover evidence so you can articulate how the tool works in-depth. We will examine various investigation methodologies and techniques, discovering new places to find evidence and discover the tracks of a motivated suspect, who is trying to stay hidden.
The SIFT Kit Advanced consists of:New Addition! The SIFT Kit Advanced will now include a single version Helix3 Pro that will be individually licensed to each student. Helix3 Pro is a brand new acquisition and analysis framework. This license is for the current release of Helix3 Pro only and does not include the Helix Pro subscription. As a result, students will not receive access to the Helix forum, white papers, webinars, and additional Helix software downloads.
Note: The SANS Investigative Forensic Toolkit (SIFT) Advanced is included with SECURTITY 508: Computer Forensic And E-Discovery Essentials.
For those attending SEC508 at SANS NS2009 the essentials kit is available for purchase