Posts

Violent Python Quick Thoughts

Image
I eagerly pre-ordered the book Violent Python and while I’ve only had a chance to go completely through chapter 1 and pick through chapter 6, I wanted to write a quick post with my thoughts on the book. Chapter one is called introduction to Python and while the author starts off showing an example of a list, of a dictionary etc. the content quickly escalates into projects it has you work on. I’ve done a tiny bit of python coding in the past but my python was extremely rusty. Chapter one definitely helped shake the rust off. What chapter one would not be good for is teaching someone python that has no programing experience whatsoever. One perfect example is the indentation that is such a fundamental part of python is never addressed. That could be awfully confusing to someone with zero experience. I understand people with zero programming experience are not the target demographic for a book like this; it’s just one caveat to consider before recommending the book. I’ve already recommende...

SANS Index How To Guide with Pictures

Image
I got some great advice recently on creating an index for SANS exams and I wanted to write a blog post to share it with others. I took the SANS FOR 508 Computer Forensics course in 2008. It was way over my head but I had a great time and learned a ton. A few months ago I finally decided to go for my GCFA certification. I had four year old material from a course that had been completely revamped and no index. I passed the exam with a score in the 80s but it was a grueling experience. I had to rush on the last part of the exam and never felt comfortable. A few months after my GCFA exam I got an opportunity to attend a SANS SEC 504 class. I really wanted to prepare for my GCIH exam the right way so while I was at the conference I asked several individuals how they prepared their index. Most people told me that their indexes were 8-10 pages. A lot of these people had more SANS certs than I have friends so their methods obviously worked for them. My class had a teaching assistant (also SANS...

GCIH Passed

I’m a few days late in posting this but last Monday I passed my GCIH exam with a 94. SANS advisory board here I come!!! I watched the course in the On Demand format taught by Ed Skoudis and attended the live training taught by John Strand. It was very time consuming but well worth it to get the material from two world class instructors with different points of view. The key to my high score was taking some great advice from a SANS teaching assistant & mentor named Neal Bridges who encouraged me to make a detailed (mine ended up around 30 pages) index and was kind enough to show me his GSEC index so I had an idea on how to format mine. I’ll write up a blog post soon where I’ll discuss my index and show a few samples.    

Great, Another Forensics Blog

Lets address the 300# guerrilla in the room, the world needs another computer forensics blog like I need a hole in my head. This of course begs the question why I’m starting one. The answer is, I have to and I want to. I have to because it’s not enough to say “I have certs X, Y & Z, so hire me”. You need to be active in the community and having a blog is a great way to do that. I have to because you truly get a far better understanding of a topic when you have to teach it as opposed to just learn it. I doubt the local YMCA is interested in such a class so a blog it is. I want to because I’m spending such a huge amount of resources (both time and money) to learn these topics and I think that I’ll be able to help a few people start in their journey. If I fork out $3,000 + for a training, I can at least have the common decency to write out my opinions so others can make an informed decision on whether or not the training might benefit them. Right now...