Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

New York University (NYU)

Taking Memory Forensics to the Next Level

New York University (NYU) via YouTube

Overview

This course aims to enhance participants' memory forensics skills by covering topics such as the Volatility Framework, baselines, hook comparisons, whitelisting/blacklisting, and generating Indicators of Compromise (IOCs) using plugins like Cyboxer, Stalker, and Hunter. The teaching method involves a workshop-style approach with practical examples and discussions. This course is intended for cybersecurity professionals, digital forensics analysts, and individuals interested in advanced memory forensics techniques.

Syllabus

Intro
Documentation
Volatility Framework
Purpose
Methodology
Sampling
Profile Library
Baselines (continued)
Caveat: Hook comparisons
Hook comparisons (continued)
Whitelisting/Blacklisting
Indicators of Compromise (IOCs)
Cyboxer Plugin Example
Set Difference
Union
Intersection
Symmetric Difference
Multiple Profiles
Profiler Plugin (continued)
Symantecprofiler Plugin
Profiler Plugin Discussion
CybOX (IOC) generation
Stalker Plugin
Hunter Plugin
Jack Crook DFIR Challenge
Processes
Executables
Conclusion
Questions?

Taught by

NYU Tandon School of Engineering

Reviews

Start your review of Taking Memory Forensics to the Next Level

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.