2023 SANS Report Digital Forensics
2023 SANS Report Digital Forensics
Shortage of professionals
Cloud forensics
Network forensics
Memory forensics
Ransomware IR
Requires gathering, filtering, and disseminating intel to warn and stop attacks
The examiner must spot the malware, dig into the source code, and explain what
the malware is built to do if it runs on a computer system.
Requires the ability to learn the various protocols that can be used to transfer
data across different network types and the best tools to analyze each
Often ties in nicely to IR, malware analysis, ransomware, and mobile forensic
cases
Examiners must know how to collect data (because it is fragile), and they must
also know how to analyze the data
Be curious.