Timeline Analysis C...
 
Notifications
Clear all

Timeline Analysis Course interest in Midwest?

6 Posts
4 Users
0 Reactions
438 Views
(@armresl)
Noble Member
Joined: 21 years ago
Posts: 1011
Topic starter  

Is there any serious interest for a Timeline Analysis course in Indianapolis taught by Harlan or someone who looks very similar to him.

Why Indianapolis instead of the normal location for most classes (Chicago)
Indianapolis is much cheaper and is centrally located to OH, IL, KY, MI, even TN and MO

There are a lot of practitioner and LE people in the Midwest, step up and lets get a class going.
There is a price which we must meet, so with each person who can commit, the price goes down.

Please PM me if you are interested in such a course and I can update the post with interest after a week or 2.

Thanks


   
Quote
(@armresl)
Noble Member
Joined: 21 years ago
Posts: 1011
Topic starter  

Any interest?

Cmon everyone, you know you're tired of paying $30-$50 a day to park and sit in awful traffic, eat high priced junk meals, and pay for $300 Motel 5's

Post here if you want, lets get this going.


   
ReplyQuote
(@twjolson)
Honorable Member
Joined: 17 years ago
Posts: 417
 

Indianapolis is a bit far for me (Nebraska) but my interest in the subject is great. I would make a case for going to the higher ups.


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Based on some analysis that I've done recently, and as a result of conversations I've had with Corey Harrell, as well as some other folks at work, I've been updating the tools and material for the course.

I think that the biggest thing at the moment is how the edition of category identifiers can really aid in analysis. For example, I recently analyzed a Windows 2008 R2 Server, and kept having to look up the Event IDs. I decided to add the ability to map various event source/ID pairs to a category ID. For example, there are a number of event IDs associated with Terminal Services that identify a logon vs. a logoff vs. a failed logon attempt. Further, there are a number of events from the Windows Event Log as well as from other sources (UserAssist, Prefetch, ShimCache, etc.) that are all associated with program execution. Adding category IDs or "tags" allow the events themselves to be better understood.


   
ReplyQuote
(@ctaylor)
Eminent Member
Joined: 20 years ago
Posts: 27
 

PM Sent!

As this training is literally at my back door, I'm very interested!

Thanks!

C


   
ReplyQuote
(@armresl)
Noble Member
Joined: 21 years ago
Posts: 1011
Topic starter  

This thread is for loading and unloading of potential attendees of the course, there is no parking in the timeline thread.

(OK bad Airplane take on loading and unloading in a red zone)

Everyone who has PM'd me you have mail. Just waiting on information.


   
ReplyQuote
Share: