DFIR “Hunt Evil” Poster – Side 1
This poster focuses on what’s normal on a Windows host helps cut through the noise to quickly locate potential malware. Use the information on the first side as a reference to know what’s normal in Windows and to focus your attention on the outliers.
Created by FOR500 Windows Forensics Analysis and FOR508 Advanced Digital Forensics, Incident Response & Threat Hunting course author and SANS Chief Curriculum Director and Faculty Lead, Rob Lee and Principal Instructor Mike Pilkington, with support from the SANS DFIR Faculty.
The DFIR posters are shipped rolled in a tube and measure 24″ x 36″ (slightly larger than the SANS folded version).