Educause Security Discussion mailing list archives

Re: Opinions on SANS 508 Course and their VMware based Forensic analysis workstation


From: "Beechey, Jim" <beechey () NORTHWOOD EDU>
Date: Tue, 28 Jul 2009 14:38:42 -0400

Jim

I am a SANS Technology Institute masters student so I am admittedly biased.  Having said that, I can't say enough 
positive things about SANS.  I've taken quite a few classes/certs including 508 and enjoyed them all.  The forensic 
courses have recently gone through significant changes, in fact there is an entire forensic track now (see 
http://forensics.sans.org).  Rob Lee who authored several of the courses works for Mandiant and they now use Helix3Pro 
in the course so there is some nice overlap with your other options.  SANS courses are typically going to teach you 
down and dirty concepts using mostly open source tools rather than how to run a specific tool.  The only time I would 
not recommend SANS is if you're looking for something very vendor specific like you need to know how to use EnCase or 
FTK specifically.

HTH
Jim


Jim Beechey
Associate Director, Networks and Information Security
Northwood University
4000 Whiting Drive
Midland, MI 48640

989-837-4169
beechey () northwood edu<mailto:%20bwisler () northwood edu>
www.northwood.edu<https://mail.northwood.edu/exchweb/bin/redir.asp?URL=http://www.northwood.edu/>

"Developing the future leaders of a global, free-enterprise society."



From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of James 
Moore
Sent: Tuesday, July 28, 2009 2:01 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] Opinions on SANS 508 Course and their VMware based Forensic analysis workstation

I need to get better at capture of information from a live system as part of incident response.  There are a number of 
tools out there that help (Helix3Pro, Rapier, MIR-ROR), and Harlan Carvey's tools.  I haven't had time to determine how 
all of the tools change the system.  I am also doing more with VMWare, mainly restoring forensic images to virtual 
disks, and then running some of the commercial A/V and malware detection tools (but I know that the A/V vendors are 
getting overwhelmed.  The other thing is that, if I make it to where I can boot an image restored from a forensic 
image, then I can install tools that disrupt the state of the machine, as long as I do it in clones, pr with 
non-persist mode enabled.

I am looking for 1 week of training for this year which can focus on incident response, and has decent coverage of live 
tools (and an accurate description of their effects on machine state), and something about ways to use virtual machines 
(we use VMWare Workstation) in the incident response environment.

So far, I have looked at training from SANS, Mandiant, and E-Fense training, but I only have experience with SANS (and 
that was 8 years ago when they taught a course for the first time).  Advice & recommendations are appreciated.

Jim


- - - -
Jim Moore, CISSP, IAM
Senior Information Security Forensic Investigator
Rochester Institute of Technology
151 Lomb Memorial Drive
Rochester, NY 14623-5603
(585) 475-5406 (office)
(585) 255-0809 (Cell - Incident Reporting & Emergencies)
(585) 475-7920 (fax)


If you consciously try to thwart opponents, you are already late.  Miyamoto Musashi, Japanese philosopher/samurai, 1645


Risk comes from not knowing what you're doing. -Warren Buffet

CONFIDENTIALITY NOTE: The information transmitted, including attachments, is intended only for the person(s) or entity 
to which it is addressed and may contain confidential and/or privileged material. Any review, retransmission, 
dissemination or other use of, or taking of any action in reliance upon this information by persons or entities other 
than the intended recipient is prohibited. If you received this in error, please contact the sender and destroy any 
copies of this information


Current thread: