Analyzing volatile data Course
1 hour, 5 minutes
Course description
A forensic examiner only has one shot at collecting volatile data. This course covers volatile data, the structure of this data, why it's essential and the tools that are needed to obtain it. This course also covers how to examine the data and what an examiner should expect to find.Syllabus
Using volatility to analyze RAM
Video - 00:32:00
This video walks the learner through the process of memory analysis using Volatility.
GREP and using the strings command
Video - 00:10:00
This video is an overview of GREP and how to utilize it when examining memory.
RAM capture
Video - 00:14:00
This video shown how to forensically acquire memory from a live running system.
Other sources of memory
Video - 00:04:00
This video shows other files within the OS that can contain memory.
The function and structure of RAM
Video - 00:04:00
This video shows what RAM is and how it functions.
Unlock 7 days of free training
- 1,400+ hands-on courses and labs
- Certification practice exams
- Skill assessments
Plans & pricing
Infosec Skills Personal
$299 / year
- 190+ role-guided learning paths (e.g., Ethical Hacking, Threat Hunting)
- 100s of hands-on labs in cloud-hosted cyber ranges
- Custom certification practice exams (e.g., CISSP, Security+)
- Skill assessments
- Infosec peer community support
Infosec Skills Teams
$799 per license / year
- Team administration and reporting
- Dedicated client success manager
-
Single sign-on (SSO)
Easily authenticate and manage your learners by connecting to any identity provider that supports the SAML 2.0 standard.
-
Integrations via API
Retrieve training performance and engagement metrics and integrate learner data into your existing LMS or HRS.
- 190+ role-guided learning paths and assessments (e.g., Incident Response)
- 100s of hands-on labs in cloud-hosted cyber ranges
- Create and assign custom learning paths
- Custom certification practice exams (e.g., CISSP, CISA)
- Optional upgrade: Guarantee team certification with live boot camps