Professional Certificate of Digital Forensic Analysis of RAM Memory

Students

Digital forensic expert

Course category

Digital Forensics

Completed

23/06/2023

220,00

Category:
Share:

Course Description

50 hours focused on the one thing the disk never records: running processes, open connections and artefacts that vanish the moment you power the machine down. With Volatility and real memory dumps.

Duration50 hours
LevelProfessional
Format100 % online, at your own pace
Access12 months
Exam20-question test · 75 % · 60 min
PracticalRAM dump analysis · 75 %
CertificateVerifiable digital badge
Spanish companies: eligible for FUNDAE funding. If your employer pays for it, we handle the paperwork together with our partner training body. Ask us before enrolling.

Course aims

  • This course provides the student with the necessary conceptual and practical knowledge to be able to carry out a professional Digital Forensic Analysis of Windows and Linux system RAM, malware files and network connections.
  • The student will obtain the necessary knowledge to develop his own methodology and to be able to carry out his own analysis with the corresponding executive and technical reports, which can be presented in court with all the legal guarantees.

1. Introduction to forensic analysis.

  •  Concept of forensic analysis.
  • History.
  • Some real cases.

2. Legal foundations of forensic analysis.

  •  Introduction.
  • Expert’s action.
  • Expert opinion.
  • Expert and trial.

3. Forensic procedures for the acquisition of evidence.

  •  Chain of custody.
  • Anticipated evidence.
  • Preservation of evidence.
  • Identification and collection of evidence.
  • Cloning and integrity.

4. Market solutions and NIST guidance.

  • Market study on different solutions.
  • Exercise of use and use of NIST guide in forensic procedures and incidents.

5. Practical test of a forensic analysis of the RAM memory of a Linux system.

  • Technical report in practical exercise format containing:
    • Tools to carry out the analysis.
    • Scenario preparation.
    • Execution of the exercise and analysis of the results.

6. Practical test of a forensic analysis of the RAM memory of a Windows system.

  • Technical report in practical exercise format containing:
    • Tools to carry out the analysis.
    • Scenario preparation.
    • Execution of the exercise and analysis of the results.

7. Final exam and case study – JMSec Certificate of Completion

  • Final theoretical exam.
  • Ethical hacking case study.

Course structure on the study platform

Methodology

  • The course is carried out using the following elements:
    • For each lesson the student will be provided documents in PDF format.
    • The student will have to perform workshops and practical laboratories.
    • In order to demonstrate the student’s progress in the course, the student will take a final test, as well as a practical test that will be evaluated by a tutor.

     

    This course is also designed to be able to be taken offline using the different downloadable resources provided.

Students on this courseThe shortest course in the catalogue and one of the most specific
“RAM memory analysis changes what you can reconstruct from an incident. Some things only live there and vanish when you power the machine down.”Damián M.Defence sector
“The forensic-expert angle is what I was after: not just finding the evidence, but having it hold up in front of a judge.”Marta V.Criminologist

Full trainingDigital Forensic Analysis in Windows150 hours: disks, memory, malware and network traffic, with an expert-witness report template.240 €View course →

Spain