- Course
Analyze Memory with Volatility
Learn how to use Volatility to analyze memory for malicious processes, network activity, injected code, rootkits, and credential artifacts during incident response.
- Course
Analyze Memory with Volatility
Learn how to use Volatility to analyze memory for malicious processes, network activity, injected code, rootkits, and credential artifacts during incident response.
Get started today
Access this course and other top-rated tech content with one of our business plans.
Try this course for free
Access this course and other top-rated tech content with one of our individual plans.
This course is included in the libraries shown below:
- Security
What you'll learn
Memory forensics is becoming the tool of choice for incident responders to detect fileless malware and advanced attacks. In this course, Analyze Memory with Volatility, you'll learn how to acquire and forensically analyze memory with Volatility. First, you will dump the RAM, check image integrity and find the right symbol profile. Next, you will look at running processes, network connections, DLLs, and suspicious execution artifacts. Finally, you will discover hidden kernel components, recover command history and investigate credential artifacts. By the end of this course, you will have practical memory forensics skills that are needed to perform rapid incident triage and advanced investigations.