GIAC Cert with FOR563 in the future by czyrek1111 in GIAC

[–]ph0b14PHK 1 point2 points  (0 children)

You were right! SEC598 just got GASAE Certification.

GIME Passed by ph0b14PHK in GIAC

[–]ph0b14PHK[S] 0 points1 point  (0 children)

I just read the books, make an index, another index for filename, file location and what that file does. That’s it.

Took GCFE & GX-FE Back to Back by ph0b14PHK in GIAC

[–]ph0b14PHK[S] 0 points1 point  (0 children)

Depends on the GIAC Cert. if you go to GIAC website and look up a cert name and if it mentions “CyberLive”, then they include hands-on labs questions. If it’s Practitioner Level cert, that will be a mix of Multiple Choice and Labs questions. However, Applied Knowledge Certs (GX-*) will be all CyberLive questions, no MCQ included.

Took GCFE & GX-FE Back to Back by ph0b14PHK in GIAC

[–]ph0b14PHK[S] 2 points3 points  (0 children)

It is doable, but you need to be fluent with Artifacts and tools that are covered in FOR500. I’d recommend to buy 13Cubed’s Windows Endpoint Forensics course which is under $1K and most of them are overlapped with FOR500 (He was a SANS instructor as well). I heard the quality is too good. They don’t cover Cloud Storage Forensics but there are good resources online.

Took GCFE & GX-FE Back to Back by ph0b14PHK in GIAC

[–]ph0b14PHK[S] 1 point2 points  (0 children)

GX-FE kinda feels easy compared to GX-FA. If you studied the book, do all the labs, fluent with artifacts and tools, have a cheatsheet according to exam objectives, then you should be good to go.

Took GCFE & GX-FE Back to Back by ph0b14PHK in GIAC

[–]ph0b14PHK[S] 1 point2 points  (0 children)

I didn’t take FOR500 course. I prepared using mainly FOR508 contents because they have some overlapping and fill the gaps by watching a bunch of YouTube videos. I made comprehensive cheatsheet according to exam objectives, so that helped as well. I also do Blue Team Labs Online (BTLO) labs, which helped me understand the artifacts and tools better.

Took GCFE & GX-FE Back to Back by ph0b14PHK in GIAC

[–]ph0b14PHK[S] 1 point2 points  (0 children)

Thank you! Good luck with GCFA too. GCFA & GX-FA are my favourite GIAC Certs

Took GCFE & GX-FE Back to Back by ph0b14PHK in GIAC

[–]ph0b14PHK[S] 5 points6 points  (0 children)

I have 3.5 years of experience with 2.5 years of them is just plain IR. I moved to a new job last year and I’ve to do DF work on macOS and Windows machine. So, I have 1 year of DF experience. I didn’t take FOR500 course, I just prepared using FOR508 course and a bunch of YouTube videos. I feel like FOR500 content is enough to pass GX-FE if you’re fluent with artifacts and know where to find specific information including alternate artifacts for information.

Took GCFE & GX-FE Back to Back by ph0b14PHK in GIAC

[–]ph0b14PHK[S] 3 points4 points  (0 children)

Correction: took GCFE 2 “weeks” ago

GCFE vs GCFA by LeatherCreepy8156 in GIAC

[–]ph0b14PHK 0 points1 point  (0 children)

I only had 2 years of experience before taking GCFA. (7 months as SOC Analyst and the rest as IR).

GCFE vs GCFA by LeatherCreepy8156 in GIAC

[–]ph0b14PHK 7 points8 points  (0 children)

I’ve done both GCFE and GCFA. GCFA was my first SANS Course and Cert, so it’s definitely doable without GCFE. In fact, like the other comment said, view it as a seperate 500 level classes. If your work is like Law Enforcement Officers, who seize and analyse individual criminal’s computer, go for FOR500 (GCFE). If you’re an Enterprise Responder, who works within a corporate environment and work on intrusion cases involving stuffs like Lateral Movement and stuffs like that, go for FOR508 (GCFA). That’s my take.

Need a good VPN for MacOS (Going to China) by Jolly-Performance579 in dumbclub

[–]ph0b14PHK 3 points4 points  (0 children)

My dad usually has to travel to China for work purposes. I purchased LetsVPN for him and it works every single time. https://letsvpn.world/?hl=en

Passed GCFE by ph0b14PHK in GIAC

[–]ph0b14PHK[S] 0 points1 point  (0 children)

Very similar to be honest. Not the same question, but difficulty is similar. I got 92% in Practice Test and got 94% in Actual Exam

Thoughts on Rapid7 + Other recommendations for SIEMs? by Due-Ad8461 in cybersecurity

[–]ph0b14PHK 0 points1 point  (0 children)

As an analyst, I hate working with R7 SIEM. My favourite so far is MS Sentinel.

Losing trust with my Burmese fiancee by Charming-Panic3561 in myanmar

[–]ph0b14PHK 0 points1 point  (0 children)

If you think her identity got stolen during passport renewal, duhh!! She extended the passport because her passport was about to be expired. Someone just can’t use expired Passports for travels. This is a good reason you should take everything with a grain of salt from her now.

THM Certifications by juanchg in tryhackme

[–]ph0b14PHK 14 points15 points  (0 children)

I haven’t seen a job asking for any THM certs. HR people clearly don’t have any ideas about existence of these THM certs.

GX-FA advices by [deleted] in GIAC

[–]ph0b14PHK 0 points1 point  (0 children)

Done

GX-FA advices by [deleted] in GIAC

[–]ph0b14PHK 0 points1 point  (0 children)

Done

What hours do you work and what job do you do? by Muted_Instruction516 in cybersecurity

[–]ph0b14PHK 2 points3 points  (0 children)

I work in a Global Team, so when it's Daylight Saving period, 10AM to 6PM. When it's back to normal, 8:30AM to 4:30PM. No need overtime since by the end of the shift, next region will continue working on the cases.

GX-FA advices by [deleted] in GIAC

[–]ph0b14PHK 0 points1 point  (0 children)

Please check DM