Introduction to Memory Forensics with Volatility 3
Offered By: DFIRScience via YouTube
Course Description
Overview
Syllabus
 Introduction to Volatility 3 
 Install Volatility 3 on Windows
 Volatility first run check
 Find the path of your target memory image
 Get RAM image info with windows.info
 Listing installed plugins
 Get process list from RAM with windows.pslist
 Filter Volatility output with PowerShell Select-String
 Find process handles with windows.handles
 Dump a specific file from RAm with windows.dumpfile
 Dump all files related to a PID
 Check executable run options with windows.cmdline
 Find active network connections with windows.netstat
 Find local user password hash with windows.hashdump
 Analyze user actions with windows.registry.userassist
 Find and dump Registry hives from RAM with windows.registry.hivelist
 Analyze a specific Registry key from RAM with windows.registry.printkey
 Intro to Volatility 3 review
Taught by
DFIRScience
Related Courses
Foundations of Computer Science for TeachersThe University of Texas at Austin via edX Computer Forensics
Rochester Institute of Technology via edX FinTech Security and Regulation (RegTech)
The Hong Kong University of Science and Technology via Coursera Cyber Security
CEC via Swayam Fundamentos de Ciberseguridad: un enfoque práctico
Inter-American Development Bank via edX
