
Welcome to the SDF Series!
A few tips to help you get the most out of this training.
A look at what Windows systems store in RAM and its related forensic value.
Factors to consider when deciding whether or not to extract RAM.
Let's talk about hardware choices and how they affect RAM extractions.
Here are the tools I am using in class.
What we hope to accomplish in this section as well as a discussion on the different modes RAM tools use.
A look at DumpIt as a RAM extraction option.
Let's see DumpIt in action and get some experience with it.
A look a RAM Capturer as a RAM extraction option.
Let's see Ram Capturer in action and get some experience with it.
Next, let's look at Magnet's RAM Capture tool.
Let's see Magnet's RAM Capture Tool in action and get some experience with it.
Sometimes it gets a bad rap, but FTK Imager can be a valid RAM capture option. Let me explain why.
Let's see FTK Imager in action and get some experience with it.
A free forensic boot disc loaded with open source available forensic tools.
In this section I will show you a boot disc that has Inception preloaded on it and walk you through the process of running a DMA attack in order to attempt to capture RAM. First, let's take a look at what Inception is and when you may use it.
Let's take a look at using Inception with PALADIN.
This is another RAM extraction option.
A review of the class.
Thank you for joining me in another edition of the Surviving Digital Forensics series, I hope you enjoyed the class. Visit us at SUMURI.COM to learn more about the SDF series, our other training, the SDF BLOG, and more.
Follow me on Twitter @LeclairDF to keep up to date on the latest happenings and upcoming courses in the SDF series. If you have an idea for a class let me know!
Also, be sure to check out our YouTube channel: SumuriNews.
Conducting a RAM extraction as part of the computer evidence collection process is a front line examiner skill which becoming more and more in demand. A system's live memory contains an assortment of valuable forensic data. A computer analyst trained in memory forensics can dig out evidence of hidden malware processes, user activity and encryption keys or password hashes that may be critical to accesses protected data.
This class provides you with the foundation knowledge to help you make better decisions about why or why not to capture live memory. It also gives you hands on experience using a number of freely available RAM capture tools and covers the advanced topic of using Inception.
Learn why RAM extractions are important and how the data can affect your case.
Practical exercises give you hands on experience with different RAM extraction tools.
Learn how to evaluate and benchmark your RAM capture tools.
Learn how to use PALADIN to launch INCEPTION to gain access to password protected systems in order to extract RAM.
Learn all of this in about one hour using all freely available tools.