Digital Forensics & Incident Response
FOR500 → FOR508 in 14 weeks
A 14-week deep dive into post-breach work: imaging, artifact analysis, memory forensics, malware triage, timeline reconstruction, and rapid IR at enterprise scale. Mirrors SANS FOR500 (foundational artifacts) into FOR508 (advanced IR + threat hunting). Prepares for GCFE, GCIH, and GCFA.
Lessons
- Forensic Foundations & Chain of Custody
- Windows File System & Core Artifacts
- Windows Registry Forensics
- Windows Event Logs
- Browser, Email & Communications Artifacts
- Linux & macOS Artifacts
- Memory Forensics
- Malware Triage & Analysis Foundations
- Timeline Analysis & Super-Timelines
- Credential Theft & Lateral Movement Forensics
- Hybrid Cloud IR (Entra ID / Microsoft 365)
- Threat Hunting at Scale
- IR Process, Reporting & Legal
- Capstone: 5-Day APT Investigation