Description
Course Description:
This course covers how to do a Memory Forensic.
Course Objectives:
- Understanding Data
- Volatile data Forensic
- Non- Volatile data Forensic
Min Class Size: 5 Max Class Size: 50 Pre-reqs: None
Duration: 1 day (6-8 hours)
Class requirements: Laptop/PC, wi-fi access, Chrome browser, Kali Linux and Windows VM, Volatility Framework on both the VMs, Access Data FTK Imager & MAGNET RAM Capture
Course Content
- Introduction
- Understanding Data
- Volatile Data Forensic
- Registry Forensics
- Cache, cookies, and history
- Virtual Memory Forensics
- Non-Volatile Data Forensic
- System files and Logs
- Deleted Files
- HDD Analysis