Home  
  Microsoft  
  Cisco  
  CompTIA  
  CWNP  
  InfoSecurity  
  Forums  
  Blogs  
  Topsites  
  Watch free videos online  
     
  Subnet Calculator  
  Online Degrees  
  Exam Vouchers  
  Free Magazines  
     

  Watch free videos online  
   

 

Junior Member
Registered Member
 
kmornot's Avatar
 
Join Date: Mar 2006
Posts: 17

Certifications: A+,Net+,Security+,GCIH, C|EH
kmornot is on a distinguished road
Old 11-06-2008, 03:33 PM   #1 (permalink)
Default Forensic

I am currently obtaining my Comp Info Sys degree with a Forensic track. I was wondering what are some good forensic certifications to obtain. Any help will be great.

kmornot is offline   Reply With Quote

Login/register to remove this advertisement.
Senior Member
 
Join Date: Mar 2007
Posts: 12,182

dynamik is a splendid one to beholddynamik is a splendid one to beholddynamik is a splendid one to beholddynamik is a splendid one to beholddynamik is a splendid one to beholddynamik is a splendid one to beholddynamik is a splendid one to behold
Old 11-06-2008, 04:07 PM   #2 (permalink)

http://www.eccouncil.org/chfi.htm is the only one that comes to mind, but there might be others.

Edit: I got one out of three... weak



__________________
''=~('(?{'.('[-@.^~'^'+_)@*^').'"'.('@.&@-@@<@~$@^~.@^_'^')@@/^)%[%^@/*^@%*}').',$/})')

dynamik is offline   Reply With Quote
Certification Consultant
Forum Admin
 
JDMurray's Avatar
 
Join Date: Jul 2003
Location: Surf City USA
Posts: 6,430

Certifications: CISSP, SSCP, CWSP, CWNA, CWTS, Security+, Server+, Network+, A+, DHTI+, PDI+, MSIT InfoSec (CNSS 4011, 4013)
JDMurray is a name known to allJDMurray is a name known to allJDMurray is a name known to allJDMurray is a name known to allJDMurray is a name known to allJDMurray is a name known to all
Old 11-06-2008, 04:32 PM   #3 (permalink)

http://www.techexams.net/forums/viewtopic.php?t=33163



__________________
Moderator of the InfoSec, CWNP, IT Jobs, Virtualization, Java, and Microsoft Developers forums at www.techexams.net
Blog: www.techexams.net/blogs/jdmurray
LinkedIn: www.linkedin.com/in/jamesdmurray
Twitter: www.twitter.com/jdmurray

JDMurray is offline   Reply With Quote
ping 127.0.0.1
 
shednik's Avatar
 
Join Date: Feb 2007
Location: Pittsburgh, PA
Posts: 1,843

Certifications: CCNA, CCNA:S, CNSS 4011, MCP, A+, N+, L+
shednik is a jewel in the roughshednik is a jewel in the roughshednik is a jewel in the rough
Send a message via AIM to shednik Send a message via MSN to shednik
Old 11-07-2008, 12:24 AM   #4 (permalink)

Quote:
Originally Posted by dynamik
http://www.eccouncil.org/chfi.htm is the only one that comes to mind, but there might be others.

Edit: I got one out of three... weak
dynamik you're slipping...get on it!!



__________________
WIP: Masters of Infosec & CCNP

shednik is offline   Reply With Quote
Senior Member
 
Join Date: Jan 2007
Location: ::1F03:0307
Posts: 220

Certifications: CPT, OSCP, CNDA / C|EH, CHFI, SGFE, SGFA
sexion8 is on a distinguished road
Old 11-07-2008, 12:45 AM   #5 (permalink)
Default Re: Forensic

Quote:
Originally Posted by kmornot
I am currently obtaining my Comp Info Sys degree with a Forensic track. I was wondering what are some good forensic certifications to obtain. Any help will be great.
CCE to be taken seriously
http://www.certified-computer-examiner.com/

CHFI - I won't comment much since I'm now a guest "moderator/speaker/online class flunky" from time to time on EC-Council's online courses... Good for incident response! Court of law? CCE... Working @ say the FBI, NSA, Fortune 100 investigative team... CCE all the way

I'm in the Digital Forensics Association now, and they're sort of figuring out a way to sort out the posers from those in the know. The procedures, processes, etc., are being laid out now. It's difficult putting things like this together because most work and the time involved with it can be overwhelming. The vast majority of "heavyweights" in the field are keeping an eye open and getting together for DFA which is kind of cool - until polit(r)ic(k)s take over. If your serious about forensic though: CCE. If you'd like to join DFA you could ask Suzanne Widup. I'll let you track her information down



__________________
"Everything we hear is an opinion, not a fact. Everything we see is a perspective, not the truth." - Marcus Aurelius

sexion8 is offline   Reply With Quote
Junior Member
Registered Member
 
kmornot's Avatar
 
Join Date: Mar 2006
Posts: 17

Certifications: A+,Net+,Security+,GCIH, C|EH
kmornot is on a distinguished road
Old 11-07-2008, 05:31 PM   #6 (permalink)

Thank you for the great information everyone.

kmornot is offline   Reply With Quote
Junior Member
Registered Member
 
kmornot's Avatar
 
Join Date: Mar 2006
Posts: 17

Certifications: A+,Net+,Security+,GCIH, C|EH
kmornot is on a distinguished road
Old 11-07-2008, 08:03 PM   #7 (permalink)

ALso, how about the EnCase Cert is that any good?

kmornot is offline   Reply With Quote
Senior Member
 
Join Date: Jan 2007
Location: ::1F03:0307
Posts: 220

Certifications: CPT, OSCP, CNDA / C|EH, CHFI, SGFE, SGFA
sexion8 is on a distinguished road
Old 11-08-2008, 11:54 PM   #8 (permalink)

Quote:
Originally Posted by kmornot
ALso, how about the EnCase Cert is that any good?
Yes, no, yes, no, yes, no... Let's change this for a second... So you set out to learn mechanics - how to fix an engine in any car correct? Would you sign up at a school that only taught you how to fix say Acura engines?

The problem with vendor specific certifications is just that - they're vendor specific. So you're an EnCE... You know how to use EnCase. So what. There is more to forensics than running a program. There is a lot involved with filesystems, memory, cache, copying, retention of data, metadata. Forensics is not and should not be a "should I get vendor X's cert?"

Semi detailed information about forensic certifications...
http://certification.about.com/cs/se...pforensics.htm

I have EnCase, Stealth Suite, Helix, TCT, FTK, F.I.R.E., Helix and a couple of others... Personally I prefer to use Helix and intuition. I like Foundstone's toolkit, but I prefer good old fashion file carving a-la *nix: Foremost + Scalpel + dd

So ask yourself this question... You invest time and money to learn this only to get interviewed and you're asked on the spot to dissect and analyze something without EnCase... Then what? What steps would you take? See to me, it's all about versatility, a theme I will iterate over and over. Can you do it with say no tools at all? I can and have. Self-taught AFTER the forensics fact. I learned a long time ago to get to know the base of it all, everything else comes easy. Which is why many people nowadays seemed puzzled I have no choice/preference in operating systems: E.g.: "What's your favorite distro!@" ... Are you kidding? I don't have one. I'm in a terminal 90% of the time and anyone who knows me can tell you this...

Because I've been around the block, I've tried to teach myself alternative ways of doing things. Hence me never studying PERL only programming in it when it's beneficial to me. I can do the same in awk, sed, ruby, perl, python... It all depends on my mood. My choice of not settling was because I needed to know an alternative if say I was on a system with no access to perl, etc.... sed + awk would almost always be there...

E.g.: They all do the same thing:

ruby -pe 'next unless $_ =~ /something/' filename
grep something filename
awl '/something/' filename
perl -nle 'print if /something/' filename

However on different systems say one running a database, I might use ruby which might be faster for me... In another instance I might be forced to use say awk or sed or grep because I can't install ruby or perl... The end result is the same for me...

So learn the core of it all, don't rely on point and click to much. The rest comes easy and you're not trapped in a one vendor world. My two cents



__________________
"Everything we hear is an opinion, not a fact. Everything we see is a perspective, not the truth." - Marcus Aurelius

sexion8 is offline   Reply With Quote
Junior Member
Registered Member
 
kmornot's Avatar
 
Join Date: Mar 2006
Posts: 17

Certifications: A+,Net+,Security+,GCIH, C|EH
kmornot is on a distinguished road
Old 11-10-2008, 10:52 AM   #9 (permalink)

Awesome response thanks so much

kmornot is offline   Reply With Quote
Bookmarks
Go Back TechExams.net IT Certification Forums > InfoSec > Security Certifications
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off



All times are GMT. The time now is 06:48 AM.

 
 
Featured Sponsors

TrainSignal - “Hands On” computer training for IT professionals. Network+ Training, MCSE, Cisco & more! Visit Train Signal’s free training site to get loads of Free Computer Training, videos, articles and practice exams.

Preplogic - Sign up now to get Unlimited Access to PrepLogic's entire video training library. Enjoy open access to Microsoft Server 2008, CCNA, CISSP®, PMP and many more. Get Unlimited Access

 

Powered by vBulletin® Version 3.8
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0
TechExams.net © 2002 - 2010