Investigate cybercrime from initial indicators through attribution. Covers threat actor tracking, dark web investigations, cryptocurrency tracing, criminal community monitoring, and evidence collection for law enforcement support.
Investigate cybercrime through intelligence techniques that track threat actors, attribute attacks, and support law enforcement operations.
Cybercrime investigation requires blending forensics with intelligence tradecraft. FOR589 teaches the methodology for tracking criminals from initial indicators through attribution.
Investigate cybercrime:
Actor Tracking
Develop actor profiles from indicators
Track infrastructure and operations
Monitor criminal communities
Connect personas across platforms
Attribution Methods
Apply attribution frameworks
Analyze operational security failures
Correlate technical and behavioral indicators
Build attribution confidence levels
Law Enforcement Support
Produce evidence for legal proceedings
Support international cooperation
Navigate legal and jurisdictional issues
Document findings for prosecution
Hands-on exercises track simulated threat actors using real-world methodologies.
30 CPE credits across 5 intensive days.
Highlights
Master cybercrime investigation: Track threat actors across platforms, investigate dark web marketplaces and forums, analyze criminal communications, and translate findings into actionable intelligence.
20 hands-on labs: OPSEC setup, blockchain and UTXO analysis, dark web forum and marketplace access, sock puppet creation, and structured case development.
Built for investigators, threat intelligence analysts, and incident responders tracking cybercriminals. 5 days, 30 CPEs.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This listing offers one pricing dimension: a single-user license for FOR589: Cybercrime Investigations, billed as a contract and measured in units. Each unit covers one user. To train more people, you buy more units, so cost scales with the number of individual licenses you need. There are no separate tiers or size options here. The course itself is a five-day digital forensics and incident response program with hands-on labs and a capstone exercise, delivered to the licensed user.
Top-of-mind questions for buyers
What exactly does one single-user license unit cover?
One unit is a license for one named individual to take FOR589: Cybercrime Investigations. It grants that person access to the five-day course, its 20-plus hands-on labs, and the capstone exercise. The license is tied to the licensed user and is not shared across multiple people.
How does cost change if I need to train more than one person?
Cost scales directly with the number of licenses you buy. Each additional person needs their own single-user unit, since a license covers one named user. There are no volume tiers on this listing, so five people means five units. Adding people is a manual purchase, not an automatic upgrade.
Is the course material shared across users or restricted to the licensed individual?
Each unit is tied to one licensed user and is not meant to be shared. SANS restricts sharing or reusing course materials with other people. To give another team member access, you buy a separate single-user unit for that person rather than reusing one license.
www.sans.org+1
Helpful?
Vendor refund policy
Refunds available within 30 days if course not accessed.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Master tactical, operational, and strategic cyber threat intelligence skills. Learn to collect, analyze, and operationalize threat data to improve detection and response capabilities. Build intelligence products that inform security decisions across your organization. 36 CPEs.
SpyCloud Investigations accelerates cybercrime and identity threat investigations by providing CTI and SOC analysts with access to the worlds largest repository of dark web identity data recaptured from data breaches, malware infections, and successful phishing attacks. Powered by AI Insights and advanced identity correlation, the solution enables security teams to start with a single identifier and rapidly resolve investigations into insider threats, financial crimes, ransomware, threat actor attribution, platform abuse, and more. Choose from an easy-to-use SaaS console or API to use SpyCloud alongside other data sources in Maltego, Splunk, or Jupyter Notebook.
Learn to hunt for and respond to advanced persistent threats through deep forensic analysis. Covers memory forensics, malware analysis, lateral movement detection, and enterprise-scale incident response techniques for identifying sophisticated adversaries who evade standard defenses.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.