Cyber Incident Forensics Response

IACIS Cyber Incident Forensic Response

The IACIS “Cyber Incident Forensic Response” (CIFR) Training Program is a 2-week course of instruction designed to provide students with detailed study of traces left behind on computers and networks unique to intrusions and malware incidents.  At the conclusion of this course, students will have a clear understanding of responding to, and managing, intrusions and malware incidents, what artifacts are left during these incidents, and how knowledge of these artifacts can play a significant role in the forensic and investigative processes.

Through a variety of lectures, instructor-led and independent hands-on practical exercises, and independent laboratory activities, students will learn how to find traces left behind on Windows and Linux operating systems and on network devices, focusing on identifying intrusion and malware artifacts.  Students will spend a week focusing their analysis at the network level, analyzing a variety of logs, investigating network traffic captures and conducting drive analysis and imaging across a network.  Additionally, students will spend a week at the host level, focusing on intrusion and malware artifacts on Windows and Linux hosts.  Finally, students will become familiar with RAM capture and analysis, and basic malware analysis concepts.

The CIFR Training Program is designed to build on and expand one’s existing forensic knowledge and skill set and is not an entry level class.  Prospective students are expected to be proficient with Windows forensics and common forensic concepts and tools.  Students should be competent with the use of virtualization software (VMWare, VirtualBox, etc.) and, since portions of the analysis are conducted with a Linux VM, students should be competent at basic Linux file system navigation commands (ls, mkdir, etc.)  Students will be provided an analysis system during the class but will be provided instructions for bringing Windows and Linux VMs with them for use during the class. 

PREREQUISITE: Membership is provided to the student until the end of the calendar year in which the class was held, when payment is received.

AVAILABLE CLASSES:

September 18th, 2017 – September 29th, 2017  Registration is Now Open!!  (Limited to 22 students)
April 23, 2018 – May 4th, 2018  Registration is Now Open!! (Limited to 20 students)

 

LOCATION AND HOSTING AGENCY FOR THE SEPTEMBER, 2017 CLASS:

SecureWorks Europe

AFI Business Park

AFI Park 4, 5th Floor

4A Timisoara Blvd.

Bucharest, District 6

HOTEL:  No specific hotel has been designated for this training; however, the following Marriott Hotel is within three kilometers.  Other lodging options can be found within a 20-30 minute drive as well.

JW Marriott Bucharest Grand Hotel

Calea 13 Septembrie 90, Bucuresti 050726, Romania

+40 21 403 0000

 

LOCATION FOR THE APRIL 2018 CLASS:

The 2018 course will be taught at the Caribe Royale Hotel, 8101 World Center Drive, Orlando, Florida 32821 (USA).  This hotel has much more conference space than our previous hotel.  Additionally, it’s closer to the Orlando International Airport, has a much larger pool, spacious workout facility and is very close to Disney World and Universal Studios.  Registration is now open!  Please visit the “Book your Room” link at the bottom of the page.

Hotel Booking

You will find the information for your online reservation link below. If you have questions or need help with the link, please do not hesitate to ask. We appreciate your business and look forward to a successful event.

Rates are valid for the following dates:
4/21/18 thru 5/6/18
Caribe Royale is offering a special group rate of $114/night (US Government Rate)

Last day to book at the special group rate: 4/1/18

BOOK YOUR ROOM!

 

REGISTRATION:  

Existing IACIS members simply log in with your credentials and go to the products page to purchase and register for the course.

For non-IACIS members, the membership fee is waived with the purchase of the training course; however to register for the course you must complete a membership application at the time of purchase.

Apply for membership and purchase the course on the PRODUCTS PAGE.

COST: $2,795 US Dollars

  • Cancellation of this class may occur if there are insufficient students registered. In the event of a cancellation, personnel will typically be notified by e-mail within 48 hours of the registration closure date. IACIS is not responsible for any individual expenses incurred as a result of a cancellation. The limit of IACIS financial liability is a full refund of the course fee.  ***The September class is confirmed and will be held.***

****Payment for the September class MUST BE RECEIVED at least 30 days prior to the first day of class.  Payment for the April 2018 class MUST BE RECEIVED at least 45 days prior to the first day of class.  Any payment arrangements other than payment through the website or payment via invoice must be approved by the IACIS Treasurer prior to admittance into the course. Please contact the treasurer for questions and approval (treasurer@iacis.com).  Cancellations within 45 days from the start of class to 30 days from the start of class will be subject to a $150 cancellation fee. There will be no refunds within 30 days from the start of class.****

COURSE SYLLABUS:    CIFR Syllabus  CIFR Course Competencies

COURSE NOTES: Please read the following notes regarding this class:

Classes begin at 8:00 AM ET and conclude at 5:00 PM ET, each day, with a one hour lunch break. Classes will end at 5:00 PM ET on the last day of class. Please do not arrange for departing flights prior to 7:00 PM ET to allow time for travel to the airport and any security clearances.

The dress code for the conference is business casual (collared shirts and slacks). The wearing of shorts, flip flops, tank tops, etc. is not allowed in the classroom. Personal computers are not permitted in the classroom.  Students are required to attend all classes to successfully complete the program. Students who fail to meet the attendance requirements will not be issued a certificate at the conclusion of the program.