Collect and Analyze Random Access Memory
Learn how to get more and better evidence with RAM analysis.
A message from the instructor
Navigating the learning platform
Getting Set Up
Live Q&A Session
Before we begin...
How to acquire RAM
FREE PREVIEWHow to verify a RAM acquisition
FREE PREVIEWManually creating your RAM acquisition toolkit
Using a toolkit manager
RAM Acquisition with FTK Imager
RAM Acquisition with Magnet RAM Capture
RAM Acquisition with Belkasoft RAM Capturer
Test your learning
What are general analysis methods?
Hex Editor Basics
String and Hex Searches with a Hex Editor
Windows Powershell and Strings
Strings and Search-String
File carving with Photorec
Data extraction with Bulk_Extractor
Test your learning
What are advanced analysis methods?
Why care about OS-specific data structures?
Installing Python & Volatlity
Volatility 3 overview
Analyzing process memory in a RAM dump
Analyzing command execution
Analyzing network connections
Dump Windows password hashes
Windows Registry: UserAssist
Windows Registry: Hive Extraction
Windows Registry: Dump Specific Key
MemProcFS
Test your learning
Exam Instructions
Random Access Memory Analysis
This course is very beginner friendly. Explanations and examples provided are very clear and easy to understand.
This course is very beginner friendly. Explanations and examples provided are very clear and easy to understand.
Read LessRandom Access Memory is an excellent source of digital evidence but can be difficult to collect and analyze.
All DFIR Science courses include a lot of hands-on practice. We don't just talk about RAM analysis; you do RAM analysis.
RAM Acquisition in Windows and Linux
Generic analysis that works with any dataset
RAM parsing basics with Volatility 3
Understand how to use evidence from RAM