top of page

Mastering Memory Forensics: In-Depth Analysis with Volatility and Advanced Tools

Pages Count

23 Pages

Links for the courses

Unveiling Volatility 3: A Guide to Installation and Memory Analysis on Windows

and WSL : Click Me

MemProcFS/MemProcFS Analyzer: Comprehensive Analysis Guide : Click Me

Memory Forensics Using Strings and Bstrings: A Comprehensive Guide : Click Me

"Step-by-Step Guide to Uncovering Threats with Volatility: A Beginner’s Memory Forensics Walkthrough": Click Me

Baseline Analysis (baseline.py) in Memory Forensics: A Practical Guide : Click Me


-----------------------------------------------------------------------------------------------------------------------

Code Injection

Code Injection Hacker's Favorite Trick/ How to Detect It through Memory : Click Me

Part 2 Code Injection: How to Detect It : Click Me

Part 3 Code Injection: How to detect it/Finding Evil Memory/MemProcFS : Click Me


Rootkits

Understanding Rootkits: The Ultimate Cybersecurity Nightmare and Direct Kernel Object Manipulation: Click Me

Understanding Userland Hooks and Rootkits in Real-World Investigations : Click Me

-------------------------------------------------------------------------------------------------------------------


Extracting Memory Objects with MemProcFS/Volatility3/Bstrings:A Guide : Click Me


 -------------------------------------------------------------------------------------------------------------------

Disk Imaging, Memory Acquisition

Disk Imaging (Part 1) : Memory Acquisition & Encryption Checking : Click Me

Digital Forensics (Part 2): The Triage Collection - Kape vs FTK Imager : Click Me


Plugins in Detailed

Article

Link

Volatility Plugins — Plugin windows.handles Let’s Talk About it

Volatility Plugins — Plugin windows.malfind Let’s Talk About it

Volatility Plugins — Plugin windows.ldrmodules Let’s Talk About it

Volatility Plugins — Plugin windows.ssdt Let’s Talk About it

Volatility Plugins — Plugin window.psxview Let’s Talk About it

Volatility Plugins — Plugin window.modscan, ,window.modules Let’s Talk About it

Volatility Plugins — Plugin windows.drivermodule, windows.svcdiff Let’s Talk About it

Investigation Using MemProcFS

Article

Link

Moving Forward with Memory Analysis: From Volatility to MemProcFS Part 1

Moving Forward with Memory Analysis: From Volatility to MemProcFS : Part 2

Moving Forward with Memory Analysis: From Volatility to MemProcFS : Part 3


Your Instructor

Dean

Dean
bottom of page