Welcome to Mobilarian Forum - Official Symbianize forum.

Join us now to get access to all our features. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, and so, so much more. It's also quick and totally free, so what are you waiting for?

Sdf: Memory Forensics 1

Alexhost
O 0

oaxino

Alpha and Omega
Member
Access
Joined
Nov 24, 2022
Messages
30,024
Reaction score
864
Points
113
Age
35
Location
japanse
grants
₲89,699
1 years of service

014ce00af0aab17dcc61be3e62bc34f9.jpeg


Last updated 2/2019
MP4 | Video: h264, 1280x720 | Audio: AAC, 44.1 KHz
Language: English | Size: 1.34 GB | Duration: 1h 46m

Learn Windows memory forensics​

What you'll learn
Learn how to use Volatility
Learn to do a fast-triage compromise assessment
Understand plugin output for investigations
Learn the value of Windows core processes for exams

Requirements
Students need PC, Mac or Linux system (virtual machine preferred)
Willingness to learn!

Description
*** COURSE COMPLETELY REWRITTEN AND UPDATED 2019 ***Learn to use Volatility to conduct a fast-triage compromise assessment.A system's memory contains an assortment of valuable forensic data. Memory forensics can uncover evidence of compromise, malware, data spoliation and an assortment of file use and knowledge evidence - valuable skills for both incident response triage work as well as in digital forensic exams involving litigation.This class teaches students how to conduct memory forensics using Volatility.Learn how to do a fast-triage compromise assessmentLearn how to work with raw memory images, hibernation files and VM imagesLearn how to run and interpret pluginsHands-on practicals reinforce learningLearn all of this in about one hour using all freely available tools.

Overview
Section 1: Introduction

Lecture 1 Welcome & Introduction

Lecture 2 Class outline

Lecture 3 Class setup

Lecture 4 Setup information

Lecture 5 Class Downloads

Section 2: About volatility and memory forensics

Lecture 6 Section Overview

Lecture 7 Forensic value

Lecture 8 About Processes

Lecture 9 Process demo

Lecture 10 Volatility overview

Lecture 11 Volatility setup

Lecture 12 Using Volatility

Section 3: About memory images

Lecture 13 Section Overview

Lecture 14 Identifying supported OS

Lecture 15 Supported Memory Formats

Lecture 16 Live captures

Lecture 17 RAM capture fundamentals

Lecture 18 Hiberfil & crash dumps

Lecture 19 Hiberfil & crash dump locations

Lecture 20 Practical: convert hiberfil.sys file

Lecture 21 VM hosts

Section 4: Using plugins

Lecture 22 Section overview

Lecture 23 Overview of plugins

Lecture 24 Listing plugins

Lecture 25 Imageinfo

Lecture 26 KDBG scan

Lecture 27 OS upgrade issues

Lecture 28 PSLIST

Lecture 29 PSSCAN

Section 5: Triage with Volatility

Lecture 30 Section overview

Lecture 31 Reference Material

Lecture 32 Windows core processes

Lecture 33 Collect running processes

Lecture 34 PSLIST - all WinCore check

Lecture 35 PSLIST - all non-WinCore check

Lecture 36 PSLIST - singleton check

Lecture 37 PSLIST - WinCore boot time check

Lecture 38 PSSCAN - all non WinCore

Lecture 39 PSSCAN - process sort

Lecture 40 Not boot time

Section 6: Conclusion

Lecture 41 What's next?

Lecture 42 Conclusion

Lecture 43 Thank You!

Computer forensic examiners,Computer crime investigators,Computer security incident responders,Security analysts,IT professionals,Students

rapidgator.net:
You must reply in thread to view hidden text.

uploadgig.com:
You must reply in thread to view hidden text.

nitroflare.com:
You must reply in thread to view hidden text.
 
K 0

KatzSec DevOps

Alpha and Omega
Philanthropist
Access
Joined
Jan 17, 2022
Messages
606,808
Reaction score
7,818
Points
83
grants
₲58,329
2 years of service
oaxino salamat sa pag contribute. Next time always upload your files sa
Please, Log in or Register to view URLs content!
para siguradong di ma dedeadlink. Let's keep on sharing to keep our community running for good. This community is built for you and everyone to share freely. Let's invite more contributors para mabalik natin sigla ng Mobilarian at tuloy ang puyatan. :)
 
Top Bottom