
Welcome to SDF: Memory Analysis 1. This section introduces you to the class.
Class curriculum overview.
This section covers what you need for the class.
Information on how to set up a sift workstation.
Sample artifacts to use during the course.
Overview of the topics covered in the upcoming section.
This section provides an overview of the value of memory forensics in investigations.
An overview of what a process is in terms of memory forensics.
Process hacker is used to take a peek at live running processes on the window system.
This module explains Volatility.
This module goes over how to set up Volatility.
This section goes over volatility commandline usage.
Overview of the topics covered in the upcoming section.
This module teaches you how to identify supported operating systems.
This module reviews the types of memory artifact work with in Volatility.
This module discusses live memory capture techniques.
RAM capture is outside the scope of this course. Here is a resource to learn more.
This module teaches how to convert hibirfil.sys files for use with Volatility.
Module covers where different artifacts are located
Learn the process to convert a hiberfill.sys to a raw binary image file to use with Volatility.
Module teaches how to work with virtual machine snapshots for use with Volatility.
Overview of what you will learn in this section.
This module reviews many of the useful plugins.
This module shows you how to list volatility plugins for your version.
Learn to use the Imageinfo plug-in to identify the correct Volatility profile.
Learn to use the KDBGscan plug-in to identify the correct Volatility profile.
This module reviews a known issue with Windows server 2008 image files.
This module demonstrates the PLIST pluggin.
This module demonstrates the PSSCAN plugin.
Overview of what you'll learn in this section.
Reference material for this section
This module goes over the role Windows core processes have in forensic triage.
This module teaches how to collect running processes using Volatility.
This module teaches how to review windows core processes for parent child relationship deviations.
This module teaches how to review windows core processes for expected process path deviations.
Certain windows core processes should only have one instance running. This module teaches how to identify singleton deviations.
This module teaches how to triage by boot time values
This module reviews some common tricks attackers use to hide malicious processes in plain sight.
Another triage technique
This module walks you through another triage technique focusing on the time
Now that you are over the learning curve using Volatility, what's next?
A summary of the class.
Thanks for joining me in this edition of the SDF series.
*** COURSE COMPLETELY REWRITTEN AND UPDATED 2019 ***
Learn to use Volatility to conduct a fast-triage compromise assessment.
A system's memory contains an assortment of valuable forensic data. Memory forensics can uncover evidence of compromise, malware, data spoliation and an assortment of file use and knowledge evidence - valuable skills for both incident response triage work as well as in digital forensic exams involving litigation.
This class teaches students how to conduct memory forensics using Volatility.
Learn how to do a fast-triage compromise assessment
Learn how to work with raw memory images, hibernation files and VM images
Learn how to run and interpret plugins
Hands-on practicals reinforce learning
Learn all of this in about one hour using all freely available tools.