Visão Geral
Este curso aborda análise forense de memória para investigação de incidentes, identificação de processos, conexões, credenciais, artefatos e indicadores de comprometimento.
Conteúdo Programatico
Module 1: Memory Forensics Fundamentals
- Volatile memory concepts
- Memory acquisition
- Memory image integrity
- Memory analysis workflow
- Operating system memory
- Kernel and user space
- Memory artifacts
- Memory investigation
- Evidence preservation
- Memory forensic methodology
Module 2: Process Analysis
- Process structures
- Process enumeration
- Parent-child relationships
- Suspicious processes
- Hidden processes
- Process metadata
- Process execution analysis
- Malicious process identification
- Process timeline
- Process investigation
Module 3: Network Analysis
- Network connections
- Listening ports
- Remote connections
- Network artifacts
- Suspicious connections
- Command and Control indicators
- Process-to-network correlation
- Network timeline
- Network evidence
- Network investigation
Module 4: Credential and Authentication Analysis
- Authentication artifacts
- Credential exposure
- Token analysis
- Session analysis
- Privileged sessions
- Authentication anomalies
- Credential theft indicators
- Credential investigation
- Identity correlation
- Credential forensic analysis
Module 5: Malware and Rootkit Analysis
- Malware in memory
- Code injection
- Process injection indicators
- DLL analysis
- Suspicious memory regions
- Rootkit concepts
- Kernel artifacts
- Evasion indicators
- Malware identification
- Memory-based malware investigation
Module 6: Windows Memory Artifacts
- Windows kernel structures
- Registry artifacts
- Handles
- DLLs
- Services
- Drivers
- Command history artifacts
- User sessions
- Security artifacts
- Windows memory investigation
Module 7: Investigation and Timeline
- Memory artifact correlation
- Process timeline
- Network timeline
- Authentication timeline
- Malware timeline
- IOC correlation
- Attack reconstruction
- Evidence validation
- Investigation findings
- Forensic reporting
Module 8: Practical Memory Forensics
- Memory acquisition
- Image validation
- Process analysis
- Network analysis
- Credential analysis
- Malware investigation
- Timeline reconstruction
- IOC identification
- Evidence documentation
- Memory forensics case study