Brief Summary
This course dives into Windows memory forensics with a focus on using Volatility. You'll get hands-on with memory images, automate tasks with scripting, and learn to identify and analyze malware, all within a chill one-hour session with free tools. Easy peasy, right?
Key Points
-
Learn Windows memory forensics using Volatility
-
Hands-on training with memory images to find evidence of compromise
-
Script automation for running plugins and refining data
-
Triage malware compromise assessments quickly
-
Use freely available tools
Learning Outcomes
-
Gain practical skills in memory forensics using Volatility
-
Learn to automate forensic processes with scripting
-
Develop efficient techniques for identifying malware
-
Understand how to interpret plugin outputs for investigations
-
Acquire a comprehensive methodology for Windows memory exams
About This Course
Learn Windows memory forensics
Learn to script Volatility and conduct a malware compromise assessment.
This class provides you with hands on training working with a memory image in order to find evidence of compromise. Step-by-step the course teaches students how to automate memory forensic processing as well as how to interpret the findings. By the end of the course students will have an efficient forensic tool and methodology that may be used for any windows memory forensic exam.
This class teaches students how to conduct memory forensics using Volatility.
Learn how to use & combine plugin results to identify malware
Learn how to create a script to automate running plugins and post-processing data refinement
Learn how to run and interpret plugins
Hands-on practicals reinforce learning
Learn all of this in about one hour using all freely available tools.
Learn how to use Volatility
Learn to do a fast-triage malware compromise assessment
Understand plugin output for investigations
Neeraj R.
The course revolves around a script and a walk through of it instead of the actuals hands on. The topics were already covered in SDF1, same thing is explained here via script which doesn't make sense with the Title 2.
Half of the course is useless for someone already done SDF 1, moreover the script doesn't run, neither creates desired /exports and results as shown