What’s new in FOR572: Advanced Network Forensics - Threat Hunting, Analysis, and Incident Response

Поделиться
HTML-код
  • Опубликовано: 30 июл 2024
  • All SANS courses are updated regularly to ensure they include the latest investigative tools, techniques, and procedures, as well as reflect trends in attacker methodologies. In this webcast, Phil Hagen will discuss the latest updates in the course, as well as some exciting developments in the OnDemand delivery for the course. Well also discuss the corresponding Network Forensics poster, which was released coincident with the new course version.
    For more information about FOR572, please visit: www.sans.org/FOR572
    Speaker Bio
    Philip Hagen
    Phil Hagen is the course lead and author of FOR572, Advanced Network Forensics and Analysis, a course that provides a hands-on curriculum on the skills necessary to perform investigations of network-based incidents, where the hard drives or memory of compromised systems are often missing. He is also a DFIR Strategist at Red Canary. Phil started his career as part of a specialization within the computer science department at the U.S. Air Force Academy, where he focused on network security and was an inaugural member of the computer security extracurricular group. He served in the U.S. Air Force as a communications officer at Beale AFB and the Pentagon, and then in 2003 Phil moved over to a position with a government contractor, providing technical services for various IT and information security projects. Now 18 years later, Phil's work has spanned the full life cycle of attacks--tool development, deployment, operational and investigative aftermath--giving him a rare opportunity to provide deep insight into the artifacts left behind. Phil has covered deep technical tasks, management of an entire computer forensic services portfolio and executive responsibilities. He's supported systems that demanded 24x7x365 functionality, managed a team of 85 computer forensic professionals in the national security sector, and provided forensic consulting services for law enforcement, government, and commercial clients. Phil also spends time developing and maintaining the SOF-ELK distribution. SOF-ELK is a virtual appliance that is pre-configured with the ELK stack (Elasticsearch, Logstash, and Kibana), and it is provided as a free tool to help the DFIR Community boost case efficiency and effectiveness. Phil is a mentor and teacher at heart, one of his biggest source of professional pride.
  • НаукаНаука

Комментарии • 1