Description
FOR509: Enterprise Cloud Forensics and Incident Response. This course prepares professionals to examine emerging evidence sources on cloud platforms such as Microsoft Azure, Amazon AWS, and Google Cloud, replacing traditional on-premises investigation methods with new analytics capabilities. This course demonstrates how each of the major cloud providers provides analysts with unique data sources that were not available in traditional environments. From monitoring network traffic to directly interacting with the hypervisor to preserve evidence, all represent a fundamental evolution in forensic tools and capabilities. The core of this training is analyzing logs, which are the primary footprint of attackers. Participants learn which logs are available on each platform, how long they are retained, how they are activated, and how to interpret the events within them. Multiple hands-on labs expose participants to real-world evidence to learn firsthand where to mine data and how to analyze it to identify malicious activity.
What you will learn
- Understanding forensic data: Understanding forensic data that is only available in the cloud.
- Implement best practices: You implement best practices in cloud logging for DFIR (Digital Forensics and Incident Response).
- Using Cloud Resources: You will learn how to use Microsoft Azure, AWS, and Google Cloud resources to collect evidence.
- Review cloud logs: Understand what logs Microsoft 365 and Google Workspace have for analysts to review.
- Familiarity with Kubernetes: You will gain a high level of understanding of Kubernetes and its log sources in any cloud.
- Migrating Forensic Processes to the Cloud: You will learn how to migrate your forensic processes to the cloud for faster data processing.
This course is suitable for people who:
- Incident Response Team Members: Individuals who may need to respond to security incidents or intrusions that impact software, infrastructure, or platforms hosted in the cloud and need to know how to identify, investigate, remediate, and recover compromised systems in the enterprise cloud.
- Threat Hunters: People who seek to more fully understand threats and learn from them in order to more effectively hunt for threats and counter their solutions.
- SOC Analysts: Individuals looking to better understand alerts, develop the skills needed to categorize events, and fully utilize cloud log resources.
- Experienced Digital Forensics Analysts: Individuals who want to enhance and enhance their understanding of cloud-based forensics.
- Information Security Professionals: Individuals who directly support and assist in responding to data breach and intrusion incidents.
- Federal agents and law enforcement professionals: Individuals who want to gain expertise in advanced intrusion investigations and incident response and expand their investigative skills beyond traditional host-based digital forensics.
- SANS FOR500, FOR508, SEC541, and SEC504 graduates: Individuals looking to add cloud-based forensics to their toolkit.
Course Description FOR509: Enterprise Cloud Forensics and Incident Response
- Publisher: SANS
- Instructor: David Cowen , Pierre Lidome , Megan Roddie-Fonseca
- Training level: Beginner to advanced
- Training duration: 31 hours and 50 minutes
- Number of lessons: 4
Course headings

Course Prerequisites FOR509: Enterprise Cloud Forensics and Incident Response
- FOR509 is an Intermediate to Advanced course that focuses on Cloud infrastructure and log analysis. This class teaches students how to make use of cloud provider created data that augments, replaces or extends the artifacts they already learned about in prior SANS classes. Students may benefit from having taken FOR500: Windows Forensic Analysis, FOR508: Advanced Incident Response, Threat Hunting, and Digital Forensics, or SEC488: Cloud Security Essentials, or from having relevant previous experience.
Course images
Sample course video
Installation Guide
After Extract, view with your favorite player.
Subtitles: None
Quality: 720p
PDF file download link
USB file download link
Video file download link
File(s) password: www.downloadly.ir
File size
91 MB, 3.02 GB, 1.5 GB
