Forensic Analysis of Recovered Memory (FARM)

D.gif

Forensic Analysis of Recovered Memory
 Next Class | TBA


Important information contained in acquired memory includes passwords, registry entries, user data, Windows Vista® BitLocker passkeys and executable code that might not be recoverable from the analysis of a dead machine. Until now the investigator would pull-the-plug from the back of the computer and retreat to the lab. What are we missing by just analyzing a "Dead Machine?"

This three day training session includes extensive hands-on labs to train investigators on various tools and methods for collecting RAM from a running machine. Topics covered include:

Using and becoming proficient with the latest memory collection and analysis software.
Manually recovering actionable information from a piece of collected memory.
Using a provided EnCase® EnScript to help automate the analysis of memory.
Decompressing and analyzing the elusive hiberfil.sys file.
Instruction on how to use a specific memory acquisition protocol allowing an investigator to acquire RAM without being logged into the system.
Techniques to quickly and reliably conduct virus/malware analysis. 
 Custom training programs can be developed to meet specific customer requirements. For additional information on our training programs, as well as scheduling information, please contact us

FREE TRAINING WITH FRED SYSTEM PURCHASE

Digital Intelligence offers free training. This limited time offer will provide a single seat in our Computer Forensics with FRED class for each FRED system purchased. This program offers a great opportunity to obtain detailed training in the operation and configuration of your new FRED system! Limited seating is available in each class under this offer so make your arrangements early. Although tuition will be covered under this program, travel, meals, and lodging will be the responsibility of the student. A credit card commitment will be required to reserve seating under this program as last minute cancellations and no-shows will be charged a  cancellation fee (otherwise no charges will be applied).