Curso Memory Forensics

  • Redes & Infraestrutura de TI

Curso Memory Forensics

24h
Visão Geral

Este curso aborda análise forense de memória para investigação de incidentes, identificação de processos, conexões, credenciais, artefatos e indicadores de comprometimento.

Objetivo

Após realizar este curso, você será capaz de:

  • Compreender memória volátil
  • Analisar processos e conexões
  • Identificar indicadores de comprometimento
  • Utilizar memória em investigações forense
Publico Alvo
  • DFIR Professionals
  • Incident Responders
  • Malware Analysts
  • Threat Hunters
Pre-Requisitos
  • Conhecimentos de Windows
  • Noções de memória de sistemas
  • Conhecimentos básicos de Digital Forensics
  • Familiaridade com processos
  • Conhecimentos básicos de incident response
Conteúdo Programatico

Module 1: Memory Forensics Fundamentals

  1. Volatile memory concepts
  2. Memory acquisition
  3. Memory image integrity
  4. Memory analysis workflow
  5. Operating system memory
  6. Kernel and user space
  7. Memory artifacts
  8. Memory investigation
  9. Evidence preservation
  10. Memory forensic methodology

Module 2: Process Analysis

  1. Process structures
  2. Process enumeration
  3. Parent-child relationships
  4. Suspicious processes
  5. Hidden processes
  6. Process metadata
  7. Process execution analysis
  8. Malicious process identification
  9. Process timeline
  10. Process investigation

Module 3: Network Analysis

  1. Network connections
  2. Listening ports
  3. Remote connections
  4. Network artifacts
  5. Suspicious connections
  6. Command and Control indicators
  7. Process-to-network correlation
  8. Network timeline
  9. Network evidence
  10. Network investigation

Module 4: Credential and Authentication Analysis

  1. Authentication artifacts
  2. Credential exposure
  3. Token analysis
  4. Session analysis
  5. Privileged sessions
  6. Authentication anomalies
  7. Credential theft indicators
  8. Credential investigation
  9. Identity correlation
  10. Credential forensic analysis

Module 5: Malware and Rootkit Analysis

  1. Malware in memory
  2. Code injection
  3. Process injection indicators
  4. DLL analysis
  5. Suspicious memory regions
  6. Rootkit concepts
  7. Kernel artifacts
  8. Evasion indicators
  9. Malware identification
  10. Memory-based malware investigation

Module 6: Windows Memory Artifacts

  1. Windows kernel structures
  2. Registry artifacts
  3. Handles
  4. DLLs
  5. Services
  6. Drivers
  7. Command history artifacts
  8. User sessions
  9. Security artifacts
  10. Windows memory investigation

Module 7: Investigation and Timeline

  1. Memory artifact correlation
  2. Process timeline
  3. Network timeline
  4. Authentication timeline
  5. Malware timeline
  6. IOC correlation
  7. Attack reconstruction
  8. Evidence validation
  9. Investigation findings
  10. Forensic reporting

Module 8: Practical Memory Forensics

  1. Memory acquisition
  2. Image validation
  3. Process analysis
  4. Network analysis
  5. Credential analysis
  6. Malware investigation
  7. Timeline reconstruction
  8. IOC identification
  9. Evidence documentation
  10. Memory forensics case study
TENHO INTERESSE

Cursos Relacionados

Curso CISCO CCNA Exame CCNA 200-125

40 horas

Curso SAP BASIS S4hana - Administração e Infraestrutura

40 horas

Curso MCSA Networking with Windows Server 2016

40 horas

Curso CCNP Route 300-101 Preparatório Para Certificação

40 horas

Curso Cloudera Cientista de Dados

32 horas

Curso VMware Instalando Configurando e Gerenciando vSphere

32 horas

Curso de Redes TCP/IP - Protocolo de Redes de Computadores

40 horas

Curso Cisco Switched Networks 300-115

40 horas

Curso Wireless LAN Foundations

16 horas

Curso Certified Network Defender Certification

40 horas