<?xml version="1.0" encoding="UTF-8"?>        <rss version="2.0"
             xmlns:atom="http://www.w3.org/2005/Atom"
             xmlns:dc="http://purl.org/dc/elements/1.1/"
             xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
             xmlns:admin="http://webns.net/mvcb/"
             xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
             xmlns:content="http://purl.org/rss/1.0/modules/content/">
        <channel>
            <title>
									Sans FOR500 - Newbie to Forensics - Education and Training				            </title>
            <link>https://www.forensicfocus.com/forums/education-and-training/sans-for500-newbie-to-forensics/</link>
            <description>Digital Forensics Discussion Forums</description>
            <language>en-US</language>
            <lastBuildDate>Thu, 18 Jun 2026 04:46:33 +0000</lastBuildDate>
            <generator>wpForo</generator>
            <ttl>60</ttl>
							                    <item>
                        <title>Re: Sans FOR500 - Newbie to Forensics</title>
                        <link>https://www.forensicfocus.com/forums/education-and-training/sans-for500-newbie-to-forensics/#post-6596483</link>
                        <pubDate>Thu, 18 Oct 2018 21:22:37 +0000</pubDate>
                        <description><![CDATA[Brian Carrier&#039;s book on forensic analysis of filesystems is still a good book IMHO. Worth a read, especially if you are just starting out.Interestingly where File System Forensic Analysi...]]></description>
                        <content:encoded><![CDATA[<blockquote>Brian Carrier&#39;s book on forensic analysis of filesystems is still a good book IMHO. Worth a read, especially if you are just starting out.</blockquote><br />Interestingly where File System Forensic Analysis was previously one of the books people recommend being read first, now we're starting with forensic artefacts and working down to the file system. FOR 508 covers the NTFS artefacts on the second last or last day.<br /><br />Reading through FSFA is definitely recommended at some point. <br /><br />@apurva.rustagi<br />As per Investigating Windows Systems, I haven't received my copy yet but Harlan has indicated that it isn't a book on parsing artefacts, but about putting them together. Can't really say if its worth reading for your purpose (but considering the reviews so far, as well as knowing harlan delivers a good read), but I'd definitely be starting with the earlier books.<br /><br />Either way, doing a bit of reading beforehand, even if its just reading the weekly blog posts by everyone leading up until the course will help you hit the ground running]]></content:encoded>
						                            <category domain="https://www.forensicfocus.com/forums/education-and-training/">Education and Training</category>                        <dc:creator>randomaccess</dc:creator>
                        <guid isPermaLink="true">https://www.forensicfocus.com/forums/education-and-training/sans-for500-newbie-to-forensics/#post-6596483</guid>
                    </item>
				                    <item>
                        <title>Re: Sans FOR500 - Newbie to Forensics</title>
                        <link>https://www.forensicfocus.com/forums/education-and-training/sans-for500-newbie-to-forensics/#post-6596476</link>
                        <pubDate>Thu, 18 Oct 2018 15:44:03 +0000</pubDate>
                        <description><![CDATA[Awesome thanks a lot everyone for the detailed informative responses, very much appreciated!!]]></description>
                        <content:encoded><![CDATA[Awesome thanks a lot everyone for the detailed informative responses, very much appreciated!!]]></content:encoded>
						                            <category domain="https://www.forensicfocus.com/forums/education-and-training/">Education and Training</category>                        <dc:creator>edman</dc:creator>
                        <guid isPermaLink="true">https://www.forensicfocus.com/forums/education-and-training/sans-for500-newbie-to-forensics/#post-6596476</guid>
                    </item>
				                    <item>
                        <title>Re: Sans FOR500 - Newbie to Forensics</title>
                        <link>https://www.forensicfocus.com/forums/education-and-training/sans-for500-newbie-to-forensics/#post-6596474</link>
                        <pubDate>Thu, 18 Oct 2018 14:04:09 +0000</pubDate>
                        <description><![CDATA[Secondly, could someone recommend a good beginners book(s) I could read prior to taking the course?Brian Carrier&#039;s book on forensic analysis of filesystems is still a good book IMHO. Worth a...]]></description>
                        <content:encoded><![CDATA[<blockquote>Secondly, could someone recommend a good beginners book(s) I could read prior to taking the course?</blockquote><br />Brian Carrier's book on forensic analysis of filesystems is still a good book IMHO. Worth a read, especially if you are just starting out.]]></content:encoded>
						                            <category domain="https://www.forensicfocus.com/forums/education-and-training/">Education and Training</category>                        <dc:creator>hectic_forensics</dc:creator>
                        <guid isPermaLink="true">https://www.forensicfocus.com/forums/education-and-training/sans-for500-newbie-to-forensics/#post-6596474</guid>
                    </item>
				                    <item>
                        <title>Re: Sans FOR500 - Newbie to Forensics</title>
                        <link>https://www.forensicfocus.com/forums/education-and-training/sans-for500-newbie-to-forensics/#post-6596472</link>
                        <pubDate>Thu, 18 Oct 2018 13:22:43 +0000</pubDate>
                        <description><![CDATA[FOR500 is a good class but it assumes certain basic knowledge about forensics. The class no longer spends time on acquisition or basics of digital forensics as it used to do when it was FOR4...]]></description>
                        <content:encoded><![CDATA[FOR500 is a good class but it assumes certain basic knowledge about forensics. The class no longer spends time on acquisition or basics of digital forensics as it used to do when it was FOR408. That beings said, I really like this option because the money that you spend on SANS training should ideally get you more than just basics.Considering your background in e-discovery, i would say the course is an ideal start for you.<br /><br /> To cover the basics, you can read the following books <br /><br />1. Basics of digital forensics (you already mentioned that)<br />2. Investigating Windows Systems - This is a new book written by Harlan Carvey and will serve as a great introduction and reference to Windows Forensics. The book will help you get more out of your SANS class in April. <br /><br />I hope you enjoy your class and wish you best of luck with your career in digital forensics.<br /><br />Regards,<br />Apurva R]]></content:encoded>
						                            <category domain="https://www.forensicfocus.com/forums/education-and-training/">Education and Training</category>                        <dc:creator>apurva.rustagi</dc:creator>
                        <guid isPermaLink="true">https://www.forensicfocus.com/forums/education-and-training/sans-for500-newbie-to-forensics/#post-6596472</guid>
                    </item>
				                    <item>
                        <title>Re: Sans FOR500 - Newbie to Forensics</title>
                        <link>https://www.forensicfocus.com/forums/education-and-training/sans-for500-newbie-to-forensics/#post-6596470</link>
                        <pubDate>Thu, 18 Oct 2018 13:03:15 +0000</pubDate>
                        <description><![CDATA[500 is an excellent class, but as some said before, you could easily get lost if you don&#039;t have some security or similar exposure.  If you are VERY new to DFIR, I&#039;d recommend the SEC 401 cla...]]></description>
                        <content:encoded><![CDATA[500 is an excellent class, but as some said before, you could easily get lost if you don't have some security or similar exposure.  <br /><br />If you are VERY new to DFIR, I'd recommend the SEC 401 class. It covers lots of forensic and IR basics and is still pretty detailed. However, if your job is really focused on forensic analysis alone, the 500 is best.  <br /><br />If you want to prep, lots of universities offer free online material for study and review.  I'd also read as many SANS whitepapers on forensic basics to prepare.]]></content:encoded>
						                            <category domain="https://www.forensicfocus.com/forums/education-and-training/">Education and Training</category>                        <dc:creator>jpickens</dc:creator>
                        <guid isPermaLink="true">https://www.forensicfocus.com/forums/education-and-training/sans-for500-newbie-to-forensics/#post-6596470</guid>
                    </item>
				                    <item>
                        <title>Re: Sans FOR500 - Newbie to Forensics</title>
                        <link>https://www.forensicfocus.com/forums/education-and-training/sans-for500-newbie-to-forensics/#post-6596467</link>
                        <pubDate>Thu, 18 Oct 2018 12:06:33 +0000</pubDate>
                        <description><![CDATA[I&#039;ve sat in classes when people had really never done forensics beforeThat happened to me in FOR508 -)No idea how these guys and girls define &quot;Advanced&quot;, but I went there after 5 years i...]]></description>
                        <content:encoded><![CDATA[<blockquote>I&#39;ve sat in classes when people had really never done forensics before</blockquote><br />That happened to me in FOR508 -)<br />No idea how these guys and girls define "Advanced", but I went there after 5 years in DFIR. At the same time there was a team from **** Telecom with no clues and none of them had a notebook with enough memory or hard drive space to run the SIFT workstation&#8230;so these 4 people sat around and were surfing all day until the end of the week -) That is definetly one way to burn a lot of money!<br /><br />regards,<br />Robin]]></content:encoded>
						                            <category domain="https://www.forensicfocus.com/forums/education-and-training/">Education and Training</category>                        <dc:creator>Bunnysniper</dc:creator>
                        <guid isPermaLink="true">https://www.forensicfocus.com/forums/education-and-training/sans-for500-newbie-to-forensics/#post-6596467</guid>
                    </item>
				                    <item>
                        <title>Re: Sans FOR500 - Newbie to Forensics</title>
                        <link>https://www.forensicfocus.com/forums/education-and-training/sans-for500-newbie-to-forensics/#post-6596465</link>
                        <pubDate>Thu, 18 Oct 2018 12:02:11 +0000</pubDate>
                        <description><![CDATA[It&#039;s a good overview of the variety of artefacts available on a windows system. It depends on how you define beginnerI&#039;ve sat in classes when people had really never done forensics before an...]]></description>
                        <content:encoded><![CDATA[It's a good overview of the variety of artefacts available on a windows system. <br />It depends on how you define beginner<br />I've sat in classes when people had really never done forensics before and they can get a bit lost because there is a lot of information given in a short period of time. <br /><br />I'd have a look at the course page and see what's on each day. Generally I recommend Harlan's books wfa4 and wrf2 as a good overview of a few of the data points. I don't recall it.covering email or browsers as extensively and also doesn't cover the win10 artifacts.]]></content:encoded>
						                            <category domain="https://www.forensicfocus.com/forums/education-and-training/">Education and Training</category>                        <dc:creator>randomaccess</dc:creator>
                        <guid isPermaLink="true">https://www.forensicfocus.com/forums/education-and-training/sans-for500-newbie-to-forensics/#post-6596465</guid>
                    </item>
				                    <item>
                        <title>Re: Sans FOR500 - Newbie to Forensics</title>
                        <link>https://www.forensicfocus.com/forums/education-and-training/sans-for500-newbie-to-forensics/#post-6596464</link>
                        <pubDate>Thu, 18 Oct 2018 12:02:06 +0000</pubDate>
                        <description><![CDATA[Hi All,I&#039;m completely new to Forensics and I&#039;m planning on taking the SANS FOR500 courseYes, that is a good beginning. In parallel you can start with memory forensics and from my poi...]]></description>
                        <content:encoded><![CDATA[<blockquote>Hi All,<br /><br />I&#39;m completely new to Forensics and I&#39;m planning on taking the SANS FOR500 course</blockquote><br />Yes, that is a good beginning. In parallel you can start with memory forensics and from my point of view, there is no way around Volatility atm.<br /><br />regards, <br />Robin]]></content:encoded>
						                            <category domain="https://www.forensicfocus.com/forums/education-and-training/">Education and Training</category>                        <dc:creator>Bunnysniper</dc:creator>
                        <guid isPermaLink="true">https://www.forensicfocus.com/forums/education-and-training/sans-for500-newbie-to-forensics/#post-6596464</guid>
                    </item>
				                    <item>
                        <title>Sans FOR500 - Newbie to Forensics</title>
                        <link>https://www.forensicfocus.com/forums/education-and-training/sans-for500-newbie-to-forensics/#post-6596462</link>
                        <pubDate>Thu, 18 Oct 2018 11:16:20 +0000</pubDate>
                        <description><![CDATA[Hi All,I&#039;m completely new to Forensics and I&#039;m planning on taking the SANS FOR500 course (and GCFE certification) in April. Firstly, is this course good for beginners? Secondly, could someon...]]></description>
                        <content:encoded><![CDATA[Hi All,<br /><br />I'm completely new to Forensics and I'm planning on taking the SANS FOR500 course (and GCFE certification) in April. Firstly, is this course good for beginners? <br /><br />Secondly, could someone recommend a good beginners book(s) I could read prior to taking the course? I've seen a few being recommended elsewhere (one being The Basics of Digital Forensics The Primer for Getting Started in Digital Forensics by John Sammons) but these are very US-centric - does that matter? <br /><br />A bit of background about me, I've worked in E-Discovery in London for the last eight years but I've always been interested in Forensics and I am now planning to learn more about it and transition over to working in Forensics. <br /><br />Thanks in advance for all your help!]]></content:encoded>
						                            <category domain="https://www.forensicfocus.com/forums/education-and-training/">Education and Training</category>                        <dc:creator>edman</dc:creator>
                        <guid isPermaLink="true">https://www.forensicfocus.com/forums/education-and-training/sans-for500-newbie-to-forensics/#post-6596462</guid>
                    </item>
							        </channel>
        </rss>
		