In this hands-on lab, you will learn the basics of capturing and analyzing system memory. You practice using FTK Imager and WinPmem to extract a memory dump from a Windows system. You will then use Volatility to analyze the contents of the extracted memory.
Learning Objectives
Understand the basics of capturing and analyzing system memory. You practice using FTK Imager and WinPmem to extract a memory dump from a Windows system. You will then use Volatility to analyze the contents of the extracted memory.
Framework Connections
The materials within this course focus on the NICE Framework Task, Knowledge, and Skill statements identified within the indicated NICE Framework component(s):