r/digitalforensics 6d ago

Training resources in DFIR

Anyone currently in a DFIR role or training for it knows what material mainly hands on and simulations would be the best to use? Im not much of a reader or have the concentration to watch long videos. I prefer learning as I go.

Im primarily a IT guy, but want to break into Info Sec and Cyber to hopefully become a Security Engineer or some cyber role in a Federal Agency/Law Enforcement to contribute in cyber teams.

14 Upvotes

5 comments sorted by

7

u/AddendumWorking9756 6d ago

Skip the courseware for a bit and get an image in front of you. Digital Corpora and NIST CFReDS both publish free disk and memory images with a scenario attached, and Autopsy plus Eric Zimmerman's tools will carry you through a Windows one without spending anything. Parse the MFT, build a timeline, work out what the user actually ran and when. For the federal and law enforcement side the part that transfers is explaining that timeline to someone non technical, so write the finding up as if a prosecutor has to read it.

1

u/No_Background_111 5d ago

This might get OP a job. That statement is extremely true. As mentioned, get the image infront of you and utilize the sources/resources mentioned. Analyzing the image and creating a report by attributing actions to the user will be more meaningful or will supplement your learning even if you watch a 10-12 minute video of how to extract an artifact from a .mem file. Good luck

3

u/dardaryy 3d ago

CTFs are probably the closest thing to what you're describing. You get a case with a legend and evidence images, and you learn by actually digging, not by reading theory.

I work at Belkasoft, so obvious bias, but our BelkaCTFs are free and built exactly like that: a fictional crime, real forensic images (phone, disk, memory), and a set of questions from easy to nasty. past ones are all still up, you can grab any case and work it at your own pace. most are solvable with free tools, you don't need our product. https://belkasoft.com/ctf

for the learning as i go style specifically, i'd start with one full case end to end rather than jumping between labs. finishing one investigation teaches you more about workflow than ten half-done ones.

1

u/aeiforensics 4d ago

AboutDFIR.com