Log inSign up
SANS DFIR
33.2K posts
Image
user avatar
SANS DFIR
@sansforensics
The world's leading Digital Forensics and Incident Response provider. This feed updates you on latest DFIR news, events, and training.
digital-forensics.sans.org
Joined February 2009
104
Following
111K
Followers
  • Pinned
    user avatar
    SANS DFIR
    @sansforensics
    Apr 13
    One artifact rarely tells the full story. Jump Lists. LNK files. Prefetch. Each captures different activity on a Windows system. The challenge is connecting them. ๐Ÿ‘‡ Quick reference in the playbook ๐Ÿ‘‰ go.sans.org/RKG6xY
    Image
    00:00
    9.6K
  • user avatar
    SANS DFIR
    @sansforensics
    Aug 4, 2023
    JUST RELEASED at the #DFIRSummit the #macOS & #iOSForensicAnalysis poster This poster features "Evidence of..." categories that provide key macOS and iOS operating system artifacts that are relevant to digital investigations DOWNLOAD HERE: sans.org/u/1rPB
    Image
    39K
  • user avatar
    SANS DFIR
    @sansforensics
    Feb 24, 2025
    ๐Ÿ”ฅ In case you missed it...the NEW #CTI Cheat Sheet is now available! Packed w/ frameworks, methodologies, & tips, this guide simplifies threat modeling, tackles cognitive biases, & sharpens your analysis. ๐Ÿ“ฅ Download your FREE copy: sans.org/u/1zTr #ThreatIntel #DFIR
    Image
    21K
  • user avatar
    SANS DFIR
    @sansforensics
    Mar 4, 2025
    ๐Ÿšจ THIS JUST IN: The ultimate #Linux guide is here! Created by @4enzikat0r & @tazwake this must-have forensic poster is your go-to resource for detecting rootkits, tracking attacker persistence, & analyzing timestamps. ๐Ÿ“„ Get your FREE copy! buff.ly/pl8eiHo #DFIR
    Image
    13K
  • user avatar
    SANS DFIR
    @sansforensics
    Jun 20, 2020
    How many of the ever-so-popular SANS #DFIR posters do you have? Check them all out and download for free: sans.org/u/12CH
    Image
  • user avatar
    SANS DFIR
    @sansforensics
    Dec 15, 2017
    Congratulations to our #FOR526 co-author and instructor of many @SANSInstitute courses @MalwareJake on his promotion to Senior Instructor!
    Image
    Image
  • user avatar
    SANS DFIR
    @sansforensics
    Aug 13, 2025
    ๐Ÿ“„ The Linux #IncidentResponse & #ThreatHunting Poster by @4enzikat0r & @tazwake is your forensic roadmap, helping you analyze timestamps, track persistence mechanisms, & uncover hidden malware. ๐Ÿ“ฅ Download your FREE copy!: sans.org/u/1Avg #DFIR #Linux
    Image
    15K
  • user avatar
    SANS DFIR
    @sansforensics
    Mar 11, 2025
    ๐Ÿ“„ The Linux #IncidentResponse & #ThreatHunting Poster by @4enzikat0r & @tazwake is your forensic roadmap, helping you analyze timestamps, track persistence mechanisms, & uncover hidden malware. ๐Ÿ“ฅ Download your FREE copy!: sans.org/u/1Avg #DFIR #Linux
    Image
    12K
  • user avatar
    SANS DFIR
    @sansforensics
    Oct 12, 2024
    ๐Ÿง  Forensic analysts, meet your new best friend: the SIFT Cheat Sheet by instructor Marcus Guevara covering mounting evidence, data recovery, and more with the @SANSInstitute #SIFT Workstation. Download now! sans.org/u/1xIB #DigitalForensics #CyberSecurity #DFIR
    Image
    17K
  • user avatar
    SANS DFIR
    @sansforensics
    Feb 3, 2020
    This Valentine's Day @SANSInstitute is spreading the love by releasing the @EricZimmerman's Command Line Poster. The EZ tools provide scriptable, scalable, & repeatable results with astonishing speed and accuracy. This poster will show you how to use them. Get yours Feb 14th
    Image
  • user avatar
    SANS DFIR
    @sansforensics
    Jan 28, 2025
    ๐Ÿ”ฅ The NEW #CTI Cheat Sheet by @likethecoins & Rebekah Brown is now available! Packed w/ frameworks & methodologies this guide simplifies threat modeling, tackles cognitive biases, & sharpens your analysis. ๐Ÿ“ฅ Download your FREE copy: sans.org/u/1zTr #ThreatIntel #DFIR
    Image
    14K
  • user avatar
    SANS DFIR
    @sansforensics
    Jun 13, 2021
    JSON and jq Quick Start Guide Created by @PhilHagen and @DavidSzili, our new cheat sheet covers the basics of #JSON and some of the fundamentals of the jq utility, as a supplement to #FOR572. Download now: digital-forensics.sans.org/u/1cj6
    Image
  • user avatar
    SANS DFIR
    @sansforensics
    Aug 16, 2022
    #Austin attendees! Don't forget to get your printed #HuntEvil, #WindowsForensics, #NetworkForensics, #MobileForensics & the BRAND NEW #CloudForensics posters across the main auditorium #DFIRSummit #dfir
    Image
    Image
    Image
    Image
  • user avatar
    SANS DFIR
    @sansforensics
    Nov 27, 2022
    The #WindowsForensicAnalysis poster has been revised to support modern Windows investigations! Use it as a cheat sheet of WinXP - Windows 11 operating system artifacts & a means to discover important artifacts. Download now! ๐Ÿ‘‰sans.org/u/1nNm @chadtilbury @4enzikat0r
    Image

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Terms of Service|Privacy Policy|Cookie Policy|Accessibility|Ads info|ยฉ 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up
Advertisement
Advertisement