SDF: Memory Forensics 1

所在平台: Udemy

课程主页: https://www.udemy.com/course/surviving-digital-forensics-memory-analysis-1/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:SDF: 内存取证 1 课程概述:*** 本课程已于2019年全面重写和更新 *** 本课程旨在教授如何使用Volatility工具进行快速的妥协评估。系统内存包含大量有价值的取证数据。内存取证能够揭示妥协证据、恶意软件、数据破坏以及各种文件使用和知识证据,这些技能对事件响应和数字取证审查(涉及诉讼)都非常重要。课程将教会学生如何使用Volatility进行内存取证,学习内容包括: - 如何进行快速的妥协评估 - 如何处理原始内存映像、休眠文件和虚拟机镜像 - 如何运行和解释插件 - 通过实践操作加深理解 所有内容在大约一个小时内学习,使用的工具均为免费提供。

课程评论(0条)

课程详情

*** COURSE COMPLETELY REWRITTEN AND UPDATED 2019 ***Learn to use Volatility to conduct a fast-triage compromise assessment.A system's memory contains an assortment of valuable forensic data. Memory forensics can uncover evidence of compromise, malware, data spoliation and an assortment of file use and knowledge evidence - valuable skills for both incident response triage work as well as in digital forensic exams involving litigation.This class teaches students how to conduct memory forensics using Volatility.Learn how to do a fast-triage compromise assessmentLearn how to work with raw memory images, hibernation files and VM imagesLearn how to run and interpret pluginsHands-on practicals reinforce learningLearn all of this in about one hour using all freely available tools.

课程标签

0人关注该课程

主题相关的课程