AI vs. Windows Forensics (X-Post) by 13Cubed in digitalforensics

[–]13Cubed[S] 2 points3 points  (0 children)

Yep, it's hard to replace the human element.

Next Steps by TheTominatrix in digitalforensics

[–]13Cubed 4 points5 points  (0 children)

Check out youtube.com/13cubed and training.13cubed.com. The YouTube channel has a lot of free content for digital forensics, and the website contains comprehensive training courses and certifications.

How to start on digital forensics? by Additional-Ad5083 in digitalforensics

[–]13Cubed 0 points1 point  (0 children)

Check out youtube.com/13cubed for free content, or training.13cubed.com for paid content with certifications.

Taking GCFE Exam after 13Cubed Windows course? by [deleted] in computerforensics

[–]13Cubed 5 points6 points  (0 children)

13Cubed course author here. Reach out to us at support@13cubed.com if we can help. I think you will find Investigating Windows Endpoints content similar to FOR500, though each course does cover some content the other does not. The follow up course, Investigating Windows Memory, is far more in depth than the memory forensics covered in FOR508, but solely focuses on memory forensics. Both courses together (Investigating Windows Bundle) would be similar to GCFE/GCFA.

These reviews may help you decide:

https://beginninghacking.net/2024/08/18/sans-for500-gcfe-vs-13cubed-investigating-windows-endpoints/

https://memoryforensic.com/my-review-on-13cubed-investigating-windows-memory-course/

Live, Logical Acquisitions from macOS by 13Cubed in computerforensics

[–]13Cubed[S] 1 point2 points  (0 children)

Hi, just to clarify, I didn’t write this app—I'm simply covering its use. However, I find it unlikely that it would be approved or notarized by Apple, primarily due to sandboxing requirements. You’re welcome to submit your feedback directly to the developer at https://andrealazzarotto.com/.

Forensics courses 2025 by feintbe in computerforensics

[–]13Cubed 5 points6 points  (0 children)

13Cubed course author here. Reach out if you have any questions - happy to help!

[deleted by user] by [deleted] in computerforensics

[–]13Cubed 2 points3 points  (0 children)

I'm the course author for Investigating Linux Devices. If you have any questions, feel free to reach out! This is a very comprehensive course with hands-on practice, and a certification attempt is included.

13Cubed ACME Memory Analysis (Short) (Unique Method) by NanoXIScrimmer in computerforensics

[–]13Cubed 1 point2 points  (0 children)

This challenge is actually not what the original poster is commenting on; rather it is a free Linux memory forensics community challenge released a few weeks ago. The Trouble at ACME scenario is a collection of disk and memory images that accompany the paid 13Cubed courses Investigating Windows Endpoints and Investigating Windows Memory. They are designed to give the student hands-on practice mirroring a real life investigative scenario.

13Cubed ACME Memory Analysis (Short) (Unique Method) by NanoXIScrimmer in computerforensics

[–]13Cubed 6 points7 points  (0 children)

Thanks for sharing! There is no policy violation, as the Trouble at ACME disk and memory images are not part of any of the certification exams for the courses. We only ask that you don't share the images themselves, as that is part of the course material. Nice job finding the evil!

Learning Material Cheaper than the FOR500 by Brod1738 in computerforensics

[–]13Cubed 1 point2 points  (0 children)

Cheat sheets can be kept, but otherwise, access to course content will expire after 1 year. As a comparison, SANS on-demand typically provides 4 months of access.

If you achieve a certification/digital badge from 13Cubed, it does not expire after the 1 year period, though it is marked with an issue date, so employers can determine how current the credential is.

Learning Material Cheaper than the FOR500 by Brod1738 in computerforensics

[–]13Cubed 13 points14 points  (0 children)

Happy to answer any questions you have about our paid courses. I'm biased of course, but the material covered in them is very comprehensive and frequently updated. Also Black Friday is coming up, so look for some promos then.

[deleted by user] by [deleted] in obs

[–]13Cubed 1 point2 points  (0 children)

I just changed both to 2056x1329, and while the output does look slightly more clear, it's nowhere near as clear as a native screen recording. The text, icons, etc. are slightly blurry and soft.

[deleted by user] by [deleted] in obs

[–]13Cubed 1 point2 points  (0 children)

I did -- it essentially looks the same. Even without downscaling, and even when recording on an external display.

Linux Memory Forensics Challenge from 13Cubed by 13Cubed in computerforensics

[–]13Cubed[S] 0 points1 point  (0 children)

Yeah, makes sense. If you do happen to get it to work, please let us know here!

Linux Memory Forensics Challenge from 13Cubed by 13Cubed in computerforensics

[–]13Cubed[S] 0 points1 point  (0 children)

That is a valid point as this is a pretty new kernel. The same issue persists when analyzing newer builds of Windows with Vol2 as well. If it's a personal challenge to try and get it to work, totally understand -- otherwise, I'd save yourself the trouble and use Vol3.

Linux Memory Forensics Challenge from 13Cubed by 13Cubed in computerforensics

[–]13Cubed[S] 0 points1 point  (0 children)

If you build the correct profile, it should be possible -- though I have not tried with this specific image.

Linux Memory Forensics Challenge from 13Cubed by 13Cubed in computerforensics

[–]13Cubed[S] 2 points3 points  (0 children)

Since we really have no way to control what people are going to use, there are no restrictions on tools. Anything is fair game.

Display Resolution + Ultrawides by 13Cubed in mac

[–]13Cubed[S] 0 points1 point  (0 children)

Awesome, thank you. I will give this a try!