Visão Geral
Este curso aprofunda a análise de memória volátil para investigação de malware, processos, credenciais, conexões, injeção de código e outros artefatos relevantes para DFIR.
Conteúdo Programatico
Module 1: Advanced Memory Forensics
- Memory forensic methodology
- Volatile memory acquisition
- Memory image validation
- Windows memory architecture
- User and kernel space
- Memory artifacts
- Forensic integrity
- Memory analysis workflows
- Evidence preservation
- Advanced memory investigation
Module 2: Advanced Process Analysis
- Process structures
- Process enumeration
- Hidden processes
- Parent-child relationships
- Process injection
- Suspicious threads
- DLL analysis
- Handles
- Process artifacts
- Advanced process investigation
Module 3: Memory-Based Malware Analysis
- Malware in memory
- Code injection
- Reflective loading concepts
- Suspicious memory regions
- Injected code indicators
- Rootkit concepts
- Kernel artifacts
- Evasion techniques
- Malware identification
- Memory-based malware investigation
Module 4: Credential and Token Analysis
- Authentication artifacts
- Security tokens
- User sessions
- Privileged sessions
- Credential exposure
- Authentication anomalies
- Credential theft indicators
- Identity correlation
- Token analysis
- Credential forensic investigation
Module 5: Network Memory Forensics
- Network connections
- Listening ports
- Socket analysis
- Process-to-network correlation
- C2 indicators
- Suspicious connections
- Remote sessions
- Network timeline
- Network evidence
- Memory-based network investigation
Module 6: Advanced Windows Artifacts
- Kernel structures
- Drivers
- Services
- Registry artifacts
- Handles
- DLLs
- User sessions
- Command execution artifacts
- Security artifacts
- Windows memory artifact correlation
Module 7: Timeline and Attack Reconstruction
- Memory timelines
- Process timelines
- Network timelines
- Authentication timelines
- Malware timelines
- IOC correlation
- Attack chain reconstruction
- Evidence validation
- Investigation findings
- Forensic reporting
Module 8: Practical Memory Investigation
- Memory acquisition
- Process analysis
- Injection analysis
- Malware investigation
- Credential analysis
- Network analysis
- Timeline reconstruction
- IOC extraction
- Evidence documentation
- Memory forensics case study