This page is giving you a summary about my experience going through SANS FOR508 course and obtaining the GCFA certification.
Overview#
FOR508 Advanced Incident Response, Threat Hunting, and Digital Forensics is described with:
Apply forensic tools and techniques to investigate intrusions across enterprise systems
Perform root cause analysis using host, log, and memory artifacts
Analyze attacker activity, including persistence, lateral movement, and C2 techniques
Build and analyze timelines to reconstruct attack sequences
Use memory and host-based analysis to identify malicious activity
Counter anti-forensics techniques and recover deleted or hidden data
Use AI-assisted analysis to support data review while maintaining forensically sound practices
Section 1,
Advanced Incident Response and Threat Huntingbuilds skills tested under Enterprise Environment Incident Response and Identification of Malicious and Normal System and User Activity.Section 2,
Intrusion Analysisaligns with Windows Artifact Analysis and Identification of Malicious and Normal System and User Activity.Section 3,
Memory Forensicsin Incident Response and Threat Hunting builds skills tested under Introduction to Memory Forensics, Analyzing Volatile Malicious Event Artifacts, and Analyzing Volatile Windows Event Artifacts.Section 4,
Timeline Analysisaligns with Introduction to File System Timeline Forensics and File System Timeline Artifact Analysis.Section 5, Incident Response and Hunting Across the Enterprise / Advanced Adversary and
Anti-Forensics Detectionbuilds skills tested under NTFS Artifact Analysis and further work in Identification of Malicious System and User Activity.Section 6, The
APT Threat Group Incident Response Challengepulls all ten GCFA objectives together in one enterprise intrusion investigation across more than thirty systems.
GCFA is described with:
The GIAC Certified Forensic Analyst (GCFA®) certification validates a practitioner’s command of core forensic skills to collect and analyze data in computer systems. GCFA® certification holders have the knowledge and ability to conduct formal incident investigations and handle advanced incident handling scenarios, including internal and external data breach intrusions, advanced persistent threats (APTs), anti-forensic techniques used by attackers, and complex digital forensic cases.
I would describe FOR508 as an intermediate - advanced course in digital forensics / incident response, covering in depth windows forensics in a small (up to 30 systems) environment.
Review#
SANS FOR508 Course#
The course comes at a hefty price of currently over 9000 dollar (pun intended :D), if you’ll add the GCFA on checkout. I did the OnDemand variant, which gives you 4 month of course material access. You can keep all the labs, as you’ll do they on your own environment with two given VMs (Linux / Windows). You’ll also recieve 7 books (5 course material, 2 workbooks) and some posters. The books are only b/w printed and of rather cheap material, which is really sad for this price range.
To the course itself is top notch, very recent, fully videoed (including lab solutions) and technical in depth. There was nothing in it, which I thought “nah” I’m already too familiar in that, and I have multiple years professional experience in digital forensics. It was my first SANS course and the conclusion is yes, they are worth a lot of money. Tough in the end I don’t think that they’re worth that much.
I can’t disclose any course content (as stated in SANS NDA), but it really helped me refining my skills in incident response, learning some new interesting windows artifacts, building timelines and solving a small enterprise incident response case at the end. This last lab (section 6) is really where the crown jewel of the course lies. Up to this point you mostly got held by hand through each topic and lab. In the end you’ll need to proof you really can connect all sections and find out how the intrusion started, how the adversary moved throughout the environment, how they escalated their privileges and what was their operational goal (their intend). The given incident data was faked but in an costly way, where they setup this whole windows environment, let people work on it for multiple days, weeks and where finally an adversary (a red team) executed the breach. Through this the final lab gave the feeling of investigating a real incident.
Who is the course for?
- People having multiple years experience in
cybersecurityand / ordigital forensicsand wanting to get into the field ofincident response. - If windows forensics is new for you, you’ll should maybe do
FOR500 / GCFEorHTB CDSAfirst. What amount of time is needed? - I was through the main material (video/labs) in roughly
2 months. Preperation forGCFA(Indexing, recapping) took another month. Tough I guess I rather learned too much for the exam. My Tips for the course (OnDemand): - Don’t rush it, take your time and make good notes. That’s how you get the most out of it. I don’t think you really can absorb that much material in a live class course, as I did over my two months. I really like going forward in my own tempo. On things that you’ll understand faster you don’t have to wait for others and on things you’ll need longer you can reside as long as you want.
GCFA Exam#
You can apply for the exam without taking the FOR508 course or having the books (which technically are only obtainable via the course). I don’t think you can pass without the books. There are people on the internet claiming they have done it, but I would need to see proof that they did. Why? The exam is written straight out of the books up to the point, that you would need to know certain paragraphs/text blocks to differ between two of the four answers. On some questions I also felt they were written confusingly with intent. You’ll also have the limitiation of printed out material only (for a IT cert, really?). I’m strongly against such unnatural limitation. No one of sane mind would lookup answers in the books like this in real work, if they could just CTRL + F what they need.
The major portion is MCQ questions which tests mostly applied knowledge, which is good. The Cyberlive questions (short tasks you’ll have to do in a VM) were fair game and on point with the labs done in the course.
I passed GCFA with 93% on my first try. Tough I felt I did not learn anything from the exam itself. I got the most out of the preperation for the exam.
Timewise you get 3 hours, which is plenty of time. On practise exams as well as on the real one I finished between 1.5 - 2 hours.
Tips & Tricks for Exam#
There are already many stories for preperation for GCFA. I just write here my own two cents :).
- After the course, read through all the books (once is enough) and create yourself an index (i’ll did mine in course order per book, not alphabeticly). Goal of the index is to find topics fast.
- Doing practise exams, which you’ll get two for free if you purchase
GCFAwith aSANScourse, gives you confidence and you’ll get familiar with the exam environment. - If you do the exam in a testcenter, best thing is to ask local people which already done GIAC certs, which are good and which not. In my testcenter I got a quiet room with plenty of space for my books, which was ideal.
- Don’t stress yourself. There are thousands before you, which passed this cert.

