Skip links

Ec-council | Learning

Malware and Memory Forensics | M&MF

Malware & Memory Forensics Deep Dive

In this Malware & Memory Forensics workshop, you will learn details of how malware functions, and how it is organized. There you will be shown details of the structure of memory, and how memory works. There is plenty of hands-on memory forensics. You will learn how to analytics memory to find evidence of malware.

About the Malware and Memory Forensics Course

Outline Race

I. Types of Analysis
  • a. Swap space analysis
  • b. Memory Analysis
  • c. Data acquisition as per RFC 3227
II. In-memory data
  • a. Current processes
  • b. Memory mapped files
  • c. Hides
  • d. Open Ports
III. Memory Architectural Issues
  • a. Data structures
  • b. Windows Objects
  • c. Processes
  • d. Handles
  • e. Pool-tag scanning
  • f. %SystemDrive%/hiberfil.sys
  • g. Page/ Swap File
IV. Tools used
  • a. Using volatility
  • b. Dumpit.exe
  • c. Hibr2bin
  • d. Win32dd
  • e. Win64dd
  • f. OSForensics
V. Registry in Memory
 
 
 
 
 

This training is useful for any criminal investigator but is specifically interested in these trials to trace data leads, financial crimes, and cyber-related crimes. This workshop includes hands-on labs.

  • The purpose of the workshop is to teach students essential memory forensics; this workshop assumes a basic understanding of PCs, networks, and basic forensics.

Save big. Join the club.

If you are outside of North America and are interested in the club subscription, please click Here.

This website uses cookies to improve your web experience.
EnglishenEnglishEnglish
0