Advice on Cyber Forensics course

AsusEpoxy

Master Member
Joined
Aug 3, 2003
Messages
3,438
Reaction score
23
Hi all,

Would like to seek advice on cyber forensics courses in sg and which are the more preferred providers.

Currently doing IT system admin in a law firm and recently there are some cases which require cyber forensics skills such as cloning of hdd and phone data for expert witness purposes in court. Think having such skills will help add value to myself.

Thanks for any input!
 

davidktw

Arch-Supremacy Member
Joined
Apr 15, 2010
Messages
13,550
Reaction score
1,302
Hi all,

Would like to seek advice on cyber forensics courses in sg and which are the more preferred providers.

Currently doing IT system admin in a law firm and recently there are some cases which require cyber forensics skills such as cloning of hdd and phone data for expert witness purposes in court. Think having such skills will help add value to myself.

Thanks for any input!

Definitely. In all areas where it is cyber crimes or general security knowledge, it is always good to get yourself equipped with such information. Especially in recent months where security is greatly valued and hyped, it is something you should consider pursue if you are interested in the topic.
 

AsusEpoxy

Master Member
Joined
Aug 3, 2003
Messages
3,438
Reaction score
23
Definitely. In all areas where it is cyber crimes or general security knowledge, it is always good to get yourself equipped with such information. Especially in recent months where security is greatly valued and hyped, it is something you should consider pursue if you are interested in the topic.

thanks, any local courses to recommend? Found only Kaplan offering a Bachelor's Degree courses with certain modules dealing with cyber forensics. Not looking to get another degree. More skill specific course is probably better i think
 

davidktw

Arch-Supremacy Member
Joined
Apr 15, 2010
Messages
13,550
Reaction score
1,302

Bedokian

Senior Member
Joined
Apr 5, 2007
Messages
2,196
Reaction score
7
There are some professional certifications on cloning of HDD and phones (aka digital forensics), and their subsequent analysis, many of which are vendor specific (such as EnCE and ACE) or vendor neutral (CCE).
 

AsusEpoxy

Master Member
Joined
Aug 3, 2003
Messages
3,438
Reaction score
23
There are some professional certifications on cloning of HDD and phones (aka digital forensics), and their subsequent analysis, many of which are vendor specific (such as EnCE and ACE) or vendor neutral (CCE).

is there any course provider you recommend?
 

Bedokian

Senior Member
Joined
Apr 5, 2007
Messages
2,196
Reaction score
7
is there any course provider you recommend?

AFAIK, EnCE and ACE have local distributors and resellers who would also have some training programmes. Best to check on the EnCase and AccessData websites. As for CCE, there is no course here but it can be taken online.

Just curious, does your company use any existing tools and software for the imaging and analysis? If so, you could ask the vendor for any short courses to use these tools and software.
 

victorkk

Member
Joined
May 7, 2001
Messages
370
Reaction score
2
Hi David,

Coming from one of the classes from ThinkSecure, i think the classes are pretty informative and i definitely learned a lot from it.

However, the problem i had was this:

Although the examination is open-book and one have 2 hours to complete the examination, the setting that each wrong answer will result in "negative points", each correct answer will earn "positive points" is very stressful.

As the examination is taken at the end of the 5 days course, it is really too demanding to expect that everyone can be "pro" right after 4 days of classes. In fact, all the attendees in my class failed the exam, resulting in failed CITREP claim for all of us. All of us are from different industry with different background.

I have paid for a re-test, now practising hard to conquer the examination. :(

Do not be drawn because of cheaper course fees. It's better to pay more and get better overall package.

I'm not trying to say that ThinkSecure course are lousy. I'm just trying to point out areas that one might need to look out if its suitable for you.

I have tried SANS courses and think the course is even more rigorous and informative.

For ICS/SCADA: ICS410
For Mobile Devices: SEC575
For Forensic: FOR508

Both ThinkSecure and SANS are pretty much non-vendor specific so i think the training is much more flexible.

Good luck in getting the exposure/training you need. :)

Here might be what you are looking for ORGANIZATIONAL SYSTEMS SECURITY ANALYST(tm) Enterprise IT-Security Certification (OSSA)

Some of the courses are CITREP eligible, you might want to consider them.
 

seesiang

Member
Joined
Oct 17, 2011
Messages
415
Reaction score
5
CompTia is consider the basic certification.
EC Council is consider one of common certifications
SAN has the higher standing than EC Council
ISACA/ISC2 have the the best standing in term of security.

For hand-ons, ThinkSecure will accelerate your knowledge and equip you better if you are going for GIAC Security expert

GIAC Security Expert - GSE

One more aspect of security: Red Hat Certified Security Specialist (RHCSS) | Red Hat
 

davidktw

Arch-Supremacy Member
Joined
Apr 15, 2010
Messages
13,550
Reaction score
1,302
Hi David,

Coming from one of the classes from ThinkSecure, i think the classes are pretty informative and i definitely learned a lot from it.

However, the problem i had was this:

Although the examination is open-book and one have 2 hours to complete the examination, the setting that each wrong answer will result in "negative points", each correct answer will earn "positive points" is very stressful.

As the examination is taken at the end of the 5 days course, it is really too demanding to expect that everyone can be "pro" right after 4 days of classes. In fact, all the attendees in my class failed the exam, resulting in failed CITREP claim for all of us. All of us are from different industry with different background.

I have paid for a re-test, now practising hard to conquer the examination. :(

Do not be drawn because of cheaper course fees. It's better to pay more and get better overall package.

I'm not trying to say that ThinkSecure course are lousy. I'm just trying to point out areas that one might need to look out if its suitable for you.

I have tried SANS courses and think the course is even more rigorous and informative.

For ICS/SCADA: ICS410
For Mobile Devices: SEC575
For Forensic: FOR508

Both ThinkSecure and SANS are pretty much non-vendor specific so i think the training is much more flexible.

Good luck in getting the exposure/training you need. :)

I'm not the one taking the training and certification. However I guess since you have first hand experience, it's good advice.
 

victorkk

Member
Joined
May 7, 2001
Messages
370
Reaction score
2
Oops.
On hindsight, i should comment without "Hi Davidktw".. :p
Wonder TS has selected his training path?

I'm not the one taking the training and certification. However I guess since you have first hand experience, it's good advice.
 

hj

Senior Member
Joined
Nov 20, 2000
Messages
881
Reaction score
0
Apples vs Oranges

Hi all,

Would like to seek advice on cyber forensics courses in sg and which are the more preferred providers.

Currently doing IT system admin in a law firm and recently there are some cases which require cyber forensics skills such as cloning of hdd and phone data for expert witness purposes in court. Think having such skills will help add value to myself.

Thanks for any input!


I read the follow-up threads to the original poster's post with great interest, especially those that promoted one certification or provider over another (to me it's like saying Android vs iOS :D ) .

Here's my take :

When you compare any IT-security certification course with another, you need to make a fair comparison because no 2 courses cover exactly the same content.

For example, a general hacking-only-focused course (e.g. CEH) is strictly about attack only and does not cover other areas such as forensics, investigation, etc.

Even between different "attack-only-focused" courses, the width of the topics vs the length of the days matters since you can only cover so much within X number of days.

For example, comparing EC-Council CEH with SANS ICS410 with Thinksecure's OSWA would be an inconsistent comparison.

CEH covers many different general areas of hacking within whatever number of days while ICS410 focuses only on ICS/SCADA within whatever number of days and OSWA focuses only on WiFi/Bluetooth/RFID within whatever number of days.
All have different content and address different audiences so how can a truly objective comparison as to the superiority of one's content over the other be made?

A course covering everything hacking under the sun in 5 days is simply not going to go as deep as a course focusing on limited areas in the same 5 days because you can only fit so much into 5 days.

Similary, a course designed to focus on one area is not going to touch on other areas at all that another course that covers multiple areas not as deeply in the same time frame.

Thus, any conclusion that anyone tries to offer that a particular "brand-name" course or provider is better than another is completely subjective because, while it may be true for the person offering the conclusion, it may not be applicable for another person who may have a different set of job-related needs.

For example, stating to someone looking for a wireless hacking or web hacking course that the forensics course you attended is better and that they should go for it instead is "wen pu dui ti".

Similarly, anyone claiming that a course is bad because they found it bad for themself does not mean that it is automatically bad for everyone.

You must find out from the person making the negative statement what was their original goal or job requirement in selecting the course, why the course did not fulfil that stated goal or job requirement and to provide concrete examples of WHY it failed to meet the stated goal or job requirement instead of subjective interpretations (i.e. you need to try to find the real reason and motivation WHY they claim the course they went for is bad).

For example, i can say that ABC123XYZ Seafood Restaurant serves bad food.
But then you ask me what i like and i say i like beef and i hate seafood.
You would then know why i said the restaurant was bad - not because it is actually bad but because i hate seafood, yet i went to a seafood restaurant (i.e. it is like i am asking to be disappointed with the food). So now you know what my motivation is to slam the restaurant.

Also, a person cannot make a conclusion as to the superiority of a course by doing a comparison between 2 courses of differing content, e.g. comparing an attack-focused course that is designed to cover as many topics as possible (e.g. CEH) versus a specialized course that focuses on only ICS/SCADA (e.g. ICS410).

Whoever you look at, be it EC-Council, SANS, Thinksecure and all other certification provider websites and course leaflets, you need to compare like to like.
For example, comparing something like FOR508 which covers forensics to OSWA which covers wireless is comparing apples to oranges. Some people will prefer apples and other people will prefer oranges.



A fairer comparison yardstick between certifications in general without taking into account their actual content would be : for whatever is the given content covered, does the certification examination use performance-based testing as a measurement for passing the exam? (i.e. do you have to do some practical action to derive the answer to the question)

If you look at literature from various universities and research tanks, you will find that performance-based testing is superior to non-performance-based testing such as MCQ tests which predominate even formal high-school/secondary/tertiary education systems.
Here is one such study from the University of Texas : https://digital.library.txstate.edu/bitstream/handle/10877/3454/fulltext.pdf?sequence=1 . The conclusions and summary are inside Chapter 6 page 73 onwards. Note that essay-writing can be considered same as MCQ if candidates are told in advance the required structure to be used on the essay and the essay formula is taught as a brain-dumpable exercise.

The reason why some certifications are slammed by many people on the internet is IMO likely the result of the cost considerations of how exams are offered by providers. Performance-based testing requires some sort of exam infrastructure to be setup. And that costs more money per person to administer.
This means the provider must either pass the cost on the customer or takes a smaller profit or (more commonly) does not implement performance-based testing at all.



Having said that, the price of a course is not a completely accurate indicator of its quality.
Factors such as whether the trainers have to be flown in from overseas or not, whether there is a performance-testing exam environment, training venue, whether the training provider has a large marketing staff payroll to cover, etc, all factor into the final price you pay.
The size of your marketing payroll and how expensive your office rent is certainly does not factor into the quality of the content. In fact, lower pricing might even indicate that the provider may be more efficient operationally and passing the savings onward to the customer. I for one wouldn't mind that as a customer.

And since we don't usually have visibility into the backend ops and payroll of a provider, that is why performance-based testing is the key difference maker.

After all, you don't want to someone say to your face that a certification that you obtained solely by passing a non-performance-based-test on the back of your then-8-years of experience puts you on the same level as a 0-years experience person who only crammed for the exam via brain dumps and passed it.
This actually happened to me a long time ago in another country and i can assure you it was not a pleasant feeling to have a certification i attained just on the basis of my industry experience being downgraded just because someone could attain the same certification just by brain-dumping. That is why since that incident i became a big believer in performance-based testing because that is the only real way to make sure that my certification does not get downgraded over time.

Performance-based testing would ensure that if a person manages to get certified, he/she has earned it based on performance and not simple memorization.
So if i can get whatever is the best market price for a performance-based certification examination, that to me is always the key thing in my selection criteria.



On a related side note, as i have observed a large number of IT-related certifications proliferate over the last decade, one should always remember that the original basis of certification is to identify which individuals can do the job or not by making them pass a test which is designed to separate the wheat from the chaff.

If the pass rate of a certification exam is abnormally high or where people automatically expect to pass the exam just on the basis of exam-cramming, then the certification exam might not be stringent enough in its testing criteria and/or format.

A certification should by definition be stringent for the content that a person is being tested on such that only those who can put what they learn in a course together with all the prior work experience they have into actual real-world practice can pass.

Just compare the Cisco CCIE with its CCNA and you get the idea why there are way more CCNAs than CCIEs and why the CCIEs get paid way more.



Back to the original poster :

Since your question is specifcally about forensics-based course content, you probably want to ignore the courses in all those posts that have non-forensics content and only zoom in to do research on the courses which have forensics content and make your selection from there. Looking at the non-forensics-courses is again "wen pu dui ti". :)
Visit the course websites and download the brochures to find out the details yourself. Then call up the providers and ask to speak to someone technical and fire away. Under no circumstance talk to a marketing person about the course content and what are the takeaways !! ;)

Just make sure that whatever you select has a performance-based test to safeguard the certification's value.

Hope you find what you are looking for!
 
Last edited:
Important Forum Advisory Note
This forum is moderated by volunteer moderators who will react only to members' feedback on posts. Moderators are not employees or representatives of HWZ Forums. Forum members and moderators are responsible for their own posts. Please refer to our Community Guidelines and Standards and Terms and Conditions for more information.
Top