Incident Response Done Right: What Our SANS FOR500 Training Means for Your Business

Every organization will eventually face a security incident. It might be a phishing email that got through, a compromised account, or ransomware on a file server. What separates a bad day from a business-ending week is how the first few hours are handled.

That's why our team recently completed SANS FOR500: Windows Forensic Analysis, part of the SANS digital forensics and incident response (DFIR) curriculum. SANS is one of the most respected names in security education, and its DFIR courses are built by people who investigate real breaches for a living. This article explains what that training covers and how it shapes the way Dominant-IT responds for our clients.

For our clients in healthcare, construction, finance and insurance, an incident can mean exposed patient records, stalled projects, or compromised financial and policyholder data. The response has to be right the first time.

What DFIR actually means

DFIR combines two disciplines that have to work together:

  • Digital forensics is the careful collection and analysis of evidence: logs, disk images, memory, email headers and account activity. It answers what happened, when, and how.
  • Incident response is the coordinated effort to contain the threat, remove it, recover operations and prevent it from happening again.

Doing one without the other causes problems. Rushing to "clean up" without collecting evidence often destroys the information you need to know whether an attacker is still inside. Collecting evidence without a plan to contain the threat gives the attacker more time.

Why Windows forensics matters

Most business workstations and servers run Windows, so that's where most investigations lead. FOR500 focuses on the evidence Windows records as people and programs use a system, including:

  • The registry, which records settings, installed software, recently used files and connected USB devices.
  • Event logs, which capture logons, account changes, service installs and security events.
  • File system metadata, which shows when files were created, changed, accessed or deleted.
  • Evidence of program execution, which shows what ran on a machine and when, even after the program is gone.
  • Browser and cloud activity, which reveals downloads, visited sites and access to online storage.

Pieced together, these artifacts answer the questions that matter after an incident: who logged in, what they ran, which files they touched, and whether data left the building.

The incident response lifecycle

Most mature incident response programs follow a lifecycle similar to the one described in NIST's incident handling guidance:

  1. Preparation: plans, contacts, logging and tools in place before anything happens.
  2. Detection and analysis: recognizing that something is wrong and understanding its scope.
  3. Containment: stopping the spread, such as isolating a machine or disabling a compromised account.
  4. Eradication: removing the attacker's access and the root cause.
  5. Recovery: restoring systems and confirming they're clean.
  6. Lessons learned: documenting what happened and fixing the gaps that allowed it.

What we took away from the training

Evidence first, then cleanup. The instinct during an incident is to wipe and rebuild. Our training reinforced that key evidence, especially memory and logs, has to be preserved first. Without it, you may never know how the attacker got in or what data they touched. That matters when you have notification obligations under regulations like HIPAA.

Timelines tell the story. Combining Windows artifacts with logs from servers, firewalls and cloud accounts into a single timeline turns scattered alerts into a clear account of the attack. It shows where the attacker started, how they moved, and what they reached.

Know what normal looks like. You can't spot unusual activity without a baseline. Good logging, retained long enough to be useful, is one of the most valuable investments a business can make before an incident.

Speed matters, and so does calm. A clear playbook and defined roles prevent the panic that leads to mistakes.

How Dominant-IT applies this for clients

  • Detection around the clock. Our managed clients are monitored 24/7, with managed SOC threat detection. When something suspicious appears, we already have the context to act.
  • Fast response. Critical issues are responded to within one hour. Our first steps follow a forensic-minded process: contain the threat, preserve evidence, then remediate.
  • Incident response plans that fit you. We help clients write practical plans and runbooks: who to call, who decides, how to communicate, and what to do in the first hour.
  • Logging that's ready when you need it. We make sure critical systems log the right events and keep them long enough to investigate.
  • Tabletop exercises. Walking through a realistic scenario with your team finds the gaps before a real attacker does.
  • Post-incident reviews. Every incident ends with a clear report and specific fixes, so it doesn't happen the same way twice.

Five things you can do this week

  1. Write down who to call if you suspect a breach, including us, your insurer and legal counsel.
  2. Turn on multi-factor authentication for email and remote access, if you haven't already.
  3. Confirm you have backups that are offline or immutable, and test a restore.
  4. Check how long your firewall, server and Microsoft 365 logs are kept.
  5. Tell staff what to do if they click something suspicious: report it immediately and don't try to fix it themselves.

If you don't have an incident response plan, or you aren't sure yours would hold up, contact us. We'll help you prepare before you need it.

All articles

Talk with us about your environment

Tell us what you're running and what worries you. We'll give you a straight assessment of where you stand and what we'd do first.