Skip to content

Live Forensics Training

Evidence collection from live running systems (volatile data).

Duration: 2 days

Overview

This program teaches techniques for collecting evidence from running systems, where volatile data such as memory and network connections must be secured before it is lost.

Curriculum

What You Will Learn

  • The order-of-volatility concept
  • Memory (RAM) acquisition and dump analysis
  • Capturing network data and active connections
  • Identifying running processes and malware
  • Documenting actions taken on live systems

Who Should Attend

Incident-response and information-security teams handling active systems.

Interested in this training?

Request a schedule or an in-house program tailored to your organization.

Request Training