SANS Digital Forensics and Incident Response Blog
Access and status
Cost
Free
Free to read or download at source. No account, no purchase.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
The DFIR section of the SANS institutional blog, written by SANS instructors and course authors on topics tied to their teaching — cloud imaging, ransomware trends, mobile artifacts and case retrospectives.
Who it is for, and when
Posts are longer and more structured than most independent blogs because they are usually derived from course material, so they are a reasonable substitute when you cannot afford the course. Recent authors include Megan Roddie-Fonseca, Mari DeGrazia and Heather Barnhart, which means several practitioners whose independent blogs have gone quiet now publish here instead. Most recent DFIR post 3 September 2026.
What it does not cover
It is a marketing channel for SANS training as well as a technical blog, so posts often stop short of the depth the corresponding course delivers, and coverage follows the course catalogue rather than the field.
Go to the source
Open at sans.org (opens in a new tab)https://www.sans.org/blog/?focus-area=digital-forensics-incident-response
Details
- Type
- Blog or channel
- Written for
- Working examinerAdvancedWorking examiner, Advanced
- Topics
- training, incident-response, cloud, windows, vendor-content
- Checked at source
Related entries
Magnet Forensics' blog and resource library, mixing artifact research and how-to posts with webinars, white papers, case studies and product content across mobile, cloud, vehicle and media forensics.
CyberDefenders
Partly freeA blue-team lab platform hosting scenario-based investigations grouped as endpoint forensics, network forensics, malware analysis, cloud forensics, threat hunting, detection engineering and threat intelligence. Challenges are question-and-answer over supplied evidence, with a scoreboard.
Magnet Forensics' online DFIR conference, delivered over several weeks of sessions. The 2026 edition has taken place and its recordings are published as a free replay library, searchable by speaker, theme, language and week, covering mobile forensics, cloud investigations, video analysis and corporate investigations.
A set of eleven numbered DFIR challenges plus additional memory forensics, unallocated-space and Linux cases published by Ali Hadi, each with the scenario and the evidence to work it. Subjects include a breached web server with both disk image and memory dump, Windows user policy violation, alternate data streams, NTFS hidden-file recovery, browser artefacts, a Sysinternals-abuse malware case, encryption, and anti-forensics and data hiding.
Antisyphon Pay What You Can Training
Partly freeAntisyphon runs selected courses on a Pay What You Can model, stating that it wants to help people who cannot afford conventional training prices. Courses confirmed on the page at the time of checking are SOC Core Skills in the Age of AI with John Strand (live and on-demand) and the Professionally Evil CISSP Mentorship Program (live, multiple instructors).