Legal Cyber Academy
Blog or channelFreeCurrent

SANS Digital Forensics and Incident Response Blog

Access and status

Cost

Free

Free to read or download at source. No account, no purchase.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

The DFIR section of the SANS institutional blog, written by SANS instructors and course authors on topics tied to their teaching — cloud imaging, ransomware trends, mobile artifacts and case retrospectives.

Who it is for, and when

Posts are longer and more structured than most independent blogs because they are usually derived from course material, so they are a reasonable substitute when you cannot afford the course. Recent authors include Megan Roddie-Fonseca, Mari DeGrazia and Heather Barnhart, which means several practitioners whose independent blogs have gone quiet now publish here instead. Most recent DFIR post 3 September 2026.

What it does not cover

It is a marketing channel for SANS training as well as a technical blog, so posts often stop short of the depth the corresponding course delivers, and coverage follows the course catalogue rather than the field.

Go to the source

Open at sans.org (opens in a new tab)

https://www.sans.org/blog/?focus-area=digital-forensics-incident-response

Details

Type
Blog or channel
Written for
Working examinerAdvancedWorking examiner, Advanced
Topics
training, incident-response, cloud, windows, vendor-content
Checked at source
  • Magnet Forensics' blog and resource library, mixing artifact research and how-to posts with webinars, white papers, case studies and product content across mobile, cloud, vehicle and media forensics.

  • CyberDefenders

    Partly free

    A blue-team lab platform hosting scenario-based investigations grouped as endpoint forensics, network forensics, malware analysis, cloud forensics, threat hunting, detection engineering and threat intelligence. Challenges are question-and-answer over supplied evidence, with a scoreboard.

  • Magnet Forensics' online DFIR conference, delivered over several weeks of sessions. The 2026 edition has taken place and its recordings are published as a free replay library, searchable by speaker, theme, language and week, covering mobile forensics, cloud investigations, video analysis and corporate investigations.

  • A set of eleven numbered DFIR challenges plus additional memory forensics, unallocated-space and Linux cases published by Ali Hadi, each with the scenario and the evidence to work it. Subjects include a breached web server with both disk image and memory dump, Windows user policy violation, alternate data streams, NTFS hidden-file recovery, browser artefacts, a Sysinternals-abuse malware case, encryption, and anti-forensics and data hiding.

  • Antisyphon runs selected courses on a Pay What You Can model, stating that it wants to help people who cannot afford conventional training prices. Courses confirmed on the page at the time of checking are SOC Core Skills in the Age of AI with John Strand (live and on-demand) and the Professionally Evil CISSP Mentorship Program (live, multiple instructors).