Skip to main content

GCFA

·1230 words·6 mins
Table of Contents

This page is giving you a summary about my experience going through SANS FOR508 course and obtaining the GCFA certification.

Overview
#

FOR508 Advanced Incident Response, Threat Hunting, and Digital Forensics is described with:

  • Apply forensic tools and techniques to investigate intrusions across enterprise systems

  • Perform root cause analysis using host, log, and memory artifacts

  • Analyze attacker activity, including persistence, lateral movement, and C2 techniques

  • Build and analyze timelines to reconstruct attack sequences

  • Use memory and host-based analysis to identify malicious activity

  • Counter anti-forensics techniques and recover deleted or hidden data

  • Use AI-assisted analysis to support data review while maintaining forensically sound practices

  • Section 1, Advanced Incident Response and Threat Hunting builds skills tested under Enterprise Environment Incident Response and Identification of Malicious and Normal System and User Activity.

  • Section 2, Intrusion Analysis aligns with Windows Artifact Analysis and Identification of Malicious and Normal System and User Activity.

  • Section 3, Memory Forensics in Incident Response and Threat Hunting builds skills tested under Introduction to Memory Forensics, Analyzing Volatile Malicious Event Artifacts, and Analyzing Volatile Windows Event Artifacts.

  • Section 4, Timeline Analysis aligns with Introduction to File System Timeline Forensics and File System Timeline Artifact Analysis.

  • Section 5, Incident Response and Hunting Across the Enterprise / Advanced Adversary and Anti-Forensics Detection builds skills tested under NTFS Artifact Analysis and further work in Identification of Malicious System and User Activity.

  • Section 6, The APT Threat Group Incident Response Challenge pulls all ten GCFA objectives together in one enterprise intrusion investigation across more than thirty systems.

GCFA is described with:

The GIAC Certified Forensic Analyst (GCFA®) certification validates a practitioner’s command of core forensic skills to collect and analyze data in computer systems. GCFA® certification holders have the knowledge and ability to conduct formal incident investigations and handle advanced incident handling scenarios, including internal and external data breach intrusions, advanced persistent threats (APTs), anti-forensic techniques used by attackers, and complex digital forensic cases.

I would describe FOR508 as an intermediate - advanced course in digital forensics / incident response, covering in depth windows forensics in a small (up to 30 systems) environment.

Review
#

SANS FOR508 Course
#

The course comes at a hefty price of currently over 9000 dollar (pun intended :D), if you’ll add the GCFA on checkout. I did the OnDemand variant, which gives you 4 month of course material access. You can keep all the labs, as you’ll do they on your own environment with two given VMs (Linux / Windows). You’ll also recieve 7 books (5 course material, 2 workbooks) and some posters. The books are only b/w printed and of rather cheap material, which is really sad for this price range. To the course itself is top notch, very recent, fully videoed (including lab solutions) and technical in depth. There was nothing in it, which I thought “nah” I’m already too familiar in that, and I have multiple years professional experience in digital forensics. It was my first SANS course and the conclusion is yes, they are worth a lot of money. Tough in the end I don’t think that they’re worth that much. I can’t disclose any course content (as stated in SANS NDA), but it really helped me refining my skills in incident response, learning some new interesting windows artifacts, building timelines and solving a small enterprise incident response case at the end. This last lab (section 6) is really where the crown jewel of the course lies. Up to this point you mostly got held by hand through each topic and lab. In the end you’ll need to proof you really can connect all sections and find out how the intrusion started, how the adversary moved throughout the environment, how they escalated their privileges and what was their operational goal (their intend). The given incident data was faked but in an costly way, where they setup this whole windows environment, let people work on it for multiple days, weeks and where finally an adversary (a red team) executed the breach. Through this the final lab gave the feeling of investigating a real incident.

Who is the course for?

  • People having multiple years experience in cybersecurity and / or digital forensics and wanting to get into the field of incident response.
  • If windows forensics is new for you, you’ll should maybe do FOR500 / GCFE or HTB CDSA first. What amount of time is needed?
  • I was through the main material (video/labs) in roughly 2 months. Preperation for GCFA (Indexing, recapping) took another month. Tough I guess I rather learned too much for the exam. My Tips for the course (OnDemand):
  • Don’t rush it, take your time and make good notes. That’s how you get the most out of it. I don’t think you really can absorb that much material in a live class course, as I did over my two months. I really like going forward in my own tempo. On things that you’ll understand faster you don’t have to wait for others and on things you’ll need longer you can reside as long as you want.

GCFA Exam
#

You can apply for the exam without taking the FOR508 course or having the books (which technically are only obtainable via the course). I don’t think you can pass without the books. There are people on the internet claiming they have done it, but I would need to see proof that they did. Why? The exam is written straight out of the books up to the point, that you would need to know certain paragraphs/text blocks to differ between two of the four answers. On some questions I also felt they were written confusingly with intent. You’ll also have the limitiation of printed out material only (for a IT cert, really?). I’m strongly against such unnatural limitation. No one of sane mind would lookup answers in the books like this in real work, if they could just CTRL + F what they need. The major portion is MCQ questions which tests mostly applied knowledge, which is good. The Cyberlive questions (short tasks you’ll have to do in a VM) were fair game and on point with the labs done in the course.

I passed GCFA with 93% on my first try. Tough I felt I did not learn anything from the exam itself. I got the most out of the preperation for the exam. Timewise you get 3 hours, which is plenty of time. On practise exams as well as on the real one I finished between 1.5 - 2 hours.

Tips & Tricks for Exam
#

There are already many stories for preperation for GCFA. I just write here my own two cents :).

  • After the course, read through all the books (once is enough) and create yourself an index (i’ll did mine in course order per book, not alphabeticly). Goal of the index is to find topics fast.
  • Doing practise exams, which you’ll get two for free if you purchase GCFA with a SANS course, gives you confidence and you’ll get familiar with the exam environment.
  • If you do the exam in a testcenter, best thing is to ask local people which already done GIAC certs, which are good and which not. In my testcenter I got a quiet room with plenty of space for my books, which was ideal.
  • Don’t stress yourself. There are thousands before you, which passed this cert.