Windows Memory Forensics
MotiGraph
GCFA Advanced Certificate

Windows Memory Forensics

The evidence that only exists in RAM. Acquiring and analysing a memory image, recovering processes, network connections, injected code and credentials, and catching what disk forensics never sees.

4 lessons 210 min
  • GCFA
  • Memory Forensics
Skills

What You Will Learn in This Course

Acquire and analyse a memory image.
Recover processes and network state.
Detect injected and hidden code.
Recover credentials and secrets from memory.

About This Course

The evidence that only exists in RAM. Acquiring and analysing a memory image, recovering processes, network connections, injected code and credentials, and catching what disk forensics never sees.

Requirements

  • Windows forensics.

Who It Is For

  • GCFA-track analysts.
Curriculum

Course Content

4 items · 1 sections

  1. 01 Acquiring and analysing a memory image Preview 55 min
  2. 02 Recovering processes and network state 55 min
  3. 03 Detecting injected and hidden code 55 min
  4. 04 Recovering credentials from memory 45 min
Certified

Certificates You Can Earn

Finish your course and receive an accredited MotiGraph certificate you can add to your CV and share with employers.

MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample
MotiGraph certificate sample