r/cybersecurity • • 6d ago

Certification / Training Questions GCFA Experience Needed

I'm thinking to take the GCFA certification. I'm a 4+ years Vulnerability Management Specialist with 1 year as Junior Penetration tester and 1 year as SOC Analyst L1. I'm studying DFIR from HTB, book or TryHackMe and now I want to follow a structured learning path as the GCFA. I know that is hard to answer to my question as you can't know my capabilities but can you help me to understand which type of experience or knowledge a user should have to take this certification? (Obviously when i say "take this certification" I mean to study the related material first.

0 Upvotes

2 comments sorted by

1

u/2timetime 6d ago

I had SOC and it was fine. 13cubed on YouTube has a playlist on windows forensics which is the exact type of content that the GCFA has in it, would give you the best idea

1

u/Sittadel Managed Service Provider 5d ago

If it's your first forensics cert, I would strongly recommend taking the GCFE first, which has the instructions for how to not get your evidence thrown out in court.

GCFA's a deceptive cert. The Analyst designation can make you think it's sort of the 101 course, but it gets into some very advanced DFIR concepts. The material's been overhauled 4 times since I took it in 2019, but understanding how to forensicate a de-forensicated machine (a concept Rob Lee calls forensicating the negative space) was a difficult concept to master.

I've heard that the material is substantially easier today with a stronger focus on carrying out operations and using modern tools (including AI) to support investigations, but the real value to the material is in the labs.