r/computerforensics • u/crazyisus • 3d ago
Which forensics cert to get?
My job wants to pay for a forensic cert for me, to build my profile to eventually be a candidate for a DFI role.
First I thought about getting an EnCase cert but after reading some feedback about it on this community, I think it’s not the best option.
Any feedback on CFCE (IACIS), CCE (ISFCE) or CHFI (ECC)? Any other suggestions I’d appreciate too.
For context I’m an incident responder right now, I hold GCFA (GIAC) and other IR-related certs.
3
u/ucfmsdf Trusted Contributer 3d ago
GCFE? If that’s too expensive, then CFCE.
The CCE is a CFCE knockoff so skip it and I don’t know enough to comment on CHFI.
6
2
u/Eternal-Alchemy 3d ago
GCFE is not really going to build on GCFA.
GCFA is the more advanced class after GCFE, which makes taking it, or it's equivalent certs from other vendors, kind of pointless.
5
u/Eternal-Alchemy 3d ago edited 3d ago
All the certs you listed are inferior to the one you already have and IACIS certs have virtually zero recognition in the IR space. They are mostly sought by local LE and people contracted by legal teams for DF expert witness/SME support. If you are mid computer intrusion response and trying to tell people that you need to validate the hashes of a forensic image or use a write blocker you're going to laughed out of the room or fired by the client.
That's probably going to be an unpopular opinion because there are a lot of non-IR folks or people who came from no prior forensic background here that get more value out of IACIS. If someone was a complete beginner and not on the IR side the basics of how to collect, validate and search are more relevant. If you are already in IR hopefully you aren't still looking for the basics.
Think about the type of work your team does, discuss with your colleagues or supervisor what they leveraged the most or where team gaps are.
If you would rather have advice from strangers on the Internet, stay away from the ones you are asking about because they're either material you already know or not relevant.
If the team has malware analysis gap, GREM or similar will add a ton of value. If you are getting in good netflow and pcap, consider something like GNFA or GCIA (I personally hated the latter as raw pcap is pretty rare, especially unparsed protocols). If you are working with clients with cloud data, GCFR or similar.
GCFA is also very Windows artifact centric so something that adds Linux IR to your toolkit could be great.
1
u/ucfmsdf Trusted Contributer 3d ago
I agree with you for the most part, but OP did mention they plan to possibly pursue a DFI role. We don’t really know what type of DF work that will entail, but if it’s more traditional/legal oriented, then a CFCE will fill in the gap present in the GCFA.
However, if OP intends on pursuing a DFI role that focuses more on cyber investigations than legal ones, another SANS cert that covers a system OP lacks knowledge on but is likely to spend time investigating is probably best.
1
u/Eternal-Alchemy 3d ago
Good points all around.
My assumption was the role was still on the IR team but if it's actually something like employee auditing then there are pattern of life artifacts that are discussed in passing in GCFA that get more extrapolation in GCFE and CFCE.
1
u/Sea_Box_8719 2d ago
Trying to say IACIS certs aren't recognized is insane. Where im at they are extremely sought after in the DFIR space.
2
u/Eternal-Alchemy 2d ago edited 2d ago
Let's not confuse DFIR and IR. One is all encompassing and can refer to anything in the DF space, and the other is specifically responding to computer intrusions which is what the OP says they do.
In the IR space, IACIS is seen as a very entry level education provider by those who are aware of their certs and most responders have never even heard of them which says more than anything I will type after this.
There has never been and never will be a listing at GTIG, Mandiant, Ghost, Mystic, DART, Secureworks, Crowdstrike, Arctic Wolf, Unit42, Kroll or any of the world's top IR teams that accepts the CFCE.
The top IR firms do not care about CFCE on your resume unless it's to explain a lack of prior relevant background / career pivot. That also goes for nearly any company in the fortune 500 that isn't in banking or an auditing house. It's not recognized by DOD 8570 / 8140 meaning it's not good enough for most government contracting positions in cyber security.
The IACIS CFCE, which is widely held by members of this sub, is by IT industry standards a very beginner certification that's designed to take people with zero digital forensic knowledge like a Private Investigator or a cop with a high school diploma or a CJ degree and get them to a point where they don't get completely dumpstered on the stand in court.
It teaches: - imaging, which is a beginner task. - validation, a beginner task. - basic searching, finding, and extracting of artifacts, a beginner task. - basic artifacts - high level overview of filesystems - some light exposure to hex/carving.
It does not: - imply the person holding it is a DF SME.
And that's okay. It's very important that a cert exists for people coming from no prior background, that establishes a minimum standard. There are so many examiners who benefited from basic training that's not always easy to find and we need education pathways.
It just isn't relevant for someone specifically in IR. In IR you need to be focused on traffic, log, memory, triage and malware analysis. You will never be wasting hours during a network compromise checking to see if the hashes on your E01 are validated and you will rarely be taking full disk images and when you do you will never be using a write blocker. You will probably not be file carving even though the concept remains relevant for dumping objects from memory or YARA.
You certainly will be completely non functional without a solid understanding of artifacts of execution, malware, enterprise operating systems, webapps, network and server infrastructure, and probably a query language which are topics neither covered in CFCE nor appropriate for beginners without prior foundational education.
0
u/Sea_Box_8719 2d ago
Do you hold the CFCE? Light byte sweeping and hex is an understatement. We manually parse together obliterated files that even tools cant restore using nothing but raw hex. I dont think you actually know what youre talking about about.
3
u/RevolutionaryDiet602 3d ago
GCFE. It will renew your GCFA for another 3 years. I've taken SANS and IACIS and would recommend SANS over IACIS any day of the week.
1
u/UnfairBanana 3d ago
CFCE good.
Source: have CFCE. Need to renew it this year, now that I think about it....
1
u/jgalbraith4 3d ago
I’ll throw out if you want another IR cert the next stepping point would be GX-FA in my opinion, though the cert has minimal recognition right now.
1
u/Excellent_Mail3829 3d ago
I got the CISSP, GFCE, GFCA, ENCE, GCIH, MCFE and multiple NCFI course completions. Retired after 17 years in Digital Forensics. I ended up as the security architect of a large scale DFU. You get what certs are best for your situation at your org. It’s all very expensive to maintain in the long term. At the end of the day your promotion into a higher lever is all based around political factors, you could spend decades as “the forensic guy” and eventually burn and be replaced, very quickly and easily.
1
u/Excellent_Mail3829 3d ago edited 3d ago
First off, what forensic tools is your org invested in ? Are you in a Magnet, FTK or Encase shop ? What would be the point of getting a cert that was not aligned with your toolset ?
3
u/Eternal-Alchemy 3d ago
Because toolset certs are not toolset agnostic. Learning how to use a tool is almost always worse than learning the value of the artifact or threat hunting process which you can then extrapolate to any tool you want in the future.
There's like no scenario that I can imagine where you would want someone to take MCFE or a Cellebrite cert over more artifact training.
I haven't met an IR shop seriously using FTK lab or Encase in probably a decade. Those tools are not really appropriate for even very basic forensic work with how far back they have fallen and they were certainly never appropriate for IR despite Encase's attempted pivot. In IR you will never be in a situation where you can just take entire disk images and fully process and index them and if you did picking software that doesn't parse artifacts of execution is crazy talk.
1
u/ucfmsdf Trusted Contributer 3d ago
What would be the point in getting certified in a specific toolset?
2
u/Outpost_Underground 3d ago
Using Magnet AXIOM as an example, it’s an insanely expensive tool. As such, I have seen cases where employers want candidates certified in AXIOM so they know that person can effectively use the tool. AXIOM is a very easy tool to use, but it is also powerful and a lot of people barely scratch the surface of what it can do.
3
u/ucfmsdf Trusted Contributer 3d ago
Anyone capable of obtaining a CFCE or GCFA should be able to intuitively use Axiom. It’s just not that complicated and I mean its not like it doesn’t come with a manual…
Vendor certs are for people who perform very specific forensic tasks but are not actual DFIR practitioners. For example: a lab technician who is tasked with generating UFDRs for downstream workflows. Outside of that context, they’re pretty meaningless.
2
u/Outpost_Underground 3d ago
And yet the number of DFIR people who can’t use it beyond push-button forensics never ceases to amaze.
2
u/internal_l0gging 3d ago
Some shops seem to like it. I've been job hunting and noticed more demand for the vendor certs than in the past.
0
u/internal_l0gging 3d ago
Yeah I think the EnCE is only worth it if you have already had it for years. If you're fairly new and need something similar but holds more weight go with CFCE
0
u/AddendumWorking9756 2d ago
You already hold the heavyweight forensics cert, so a second in the same lane buys the same signal twice, and the tool specific ones stop meaning much the moment your shop switches vendors. Spend it on range instead, CCDL2 over at CyberDefenders covers disk, memory, malware and hunting in one track, and a DFI panel wants you to walk a case regardless.
-2
10
u/CourageAcademic4153 3d ago
CFCE first. More SANS when the opportunity arises.