Live Forensics Training
Evidence collection from live running systems (volatile data).
Duration: 2 days
Overview
This program teaches techniques for collecting evidence from running systems, where volatile data such as memory and network connections must be secured before it is lost.
What You Will Learn
- The order-of-volatility concept
- Memory (RAM) acquisition and dump analysis
- Capturing network data and active connections
- Identifying running processes and malware
- Documenting actions taken on live systems
Who Should Attend
Incident-response and information-security teams handling active systems.
Interested in this training?
Request a schedule or an in-house program tailored to your organization.