azmatt wrote: »
As usual, Docrice nailed it. Check out Harlan Carvey's books "Windows Forensic Analysis Toolkit Third Edition" and his book on registry forensics and you'll be in great shape.
You'll love the 408. I think it's one of the most underrated classes SANS has as a lot of people want to go straight for the "advanced" 508 class when there's a really good chance that 408 is a lot more relevant to what they do on a daily basis.
docrice wrote: »
I just wish the OnDemand specials at the moment were a bit better than the $300 value that's being offered.SANS Institute