Whatโs stored in a systemโs memory tells the story that logs and disks leave behind. In this intensive 5-day course, youโll learn how to perform forensic analysis of Windows memory at the highest level, from acquisition to advanced malware detection.
You're conducting forensic investigations but aren't yet analyzing volatile memory. As a result, you're missing evidence that exists only in RAM: active processes, hidden code, and user actions that aren't visible anywhere else.
Youโre handling complex incidents and want to reconstruct the entire attack chain. Memory analysis gives you the missing piece of the puzzleโwhat was running at the time of the compromise, and how did the attacker hide?
You work at a senior level and want to identify and analyze advanced rootkits, anti-forensic techniques, and post-exploit modules. This course will give you the in-depth knowledge you need to track down attackers who deliberately manipulate or destroy volatile data.
You will learn how to capture memory securely and in a forensically sound mannerโfrom live triage to complete memory images. You will validate the integrity of acquisitions and understand the inner workings of Windows memory structures: processes, handles, DLLs, and kernel structures.
You track down hidden and malicious code in memory dumps. You detect code injection, hollow process injection, and API hooks; investigate kernel rootkits; and uncover the self-defense techniques used by advanced malware that employs anti-forensic methods.
You analyze malicious executables statically and dynamically. You inspect PE headers, extract strings, classify malware using YARA, and track C2 communication, persistence methods, and obfuscation techniques. Tools: IDA Pro, x64dbg, YARA, process monitors.
You'll learn how to detect and respond to security incidents in AWS and Azureโfrom IAM misconfigurations to container security. You'll also use AI tools to write queries faster, summarize incidents, and generate reports that are ready for management.
Youโll build a solid foundation in malware analysis. Youโll set up a secure lab environment and perform static and dynamic analysis on real malware samples. Youโll learn to read assembly code using IDA Pro, analyze malware functionalityโdownloaders, droppers, keyloggers, C2 communication, and persistenceโand identify code injection, hooking, and obfuscation. Each section includes demonstrations and hands-on labs using real malware samples. Duration: Days 1โ3.
You perform forensic memory analysis at the highest level. You will capture memory images in a forensically sound manner, analyze them using Volatility, and reconstruct what happened on a system: processes, DLLs, network connections, registry keys, and command history. You will detect advanced techniques such as code injection, hollow process injection, API hooks, kernel rootkits, and anti-forensic methods. All components are practiced intensively using real and malware-infected memory images. Duration: Days 4โ5.
Upon completion, you will have the following demonstrable skills:
Investigators who don't analyze volatile memory are missing out on the most valuable evidence. After this training, that won't be the case anymore.
| Learning Style | Hours | Duration | Days |
|---|---|---|---|
| A full week | 32 hours | 5 days | 5 days |
| Staggered Schedule | 4 p.m. | Flexible | 2โ3 half-days per week |
With Finance4Learning, you can easily spread out your investment. The application process is quick, and weโre happy to help you work out what fits your situation. Final approval depends on your personal circumstances.
Many employers cover the full cost of the training. We will provide a detailed proposal.
Open classes for individual employees, or a customized team program. Weโll put together a well-reasoned proposal.
To participate, you must have experience in forensics and incident response, combined with in-depth knowledge of Windows, solid knowledge of Linux, and hands-on experience with Python. This is an expert-level programโnot an entry-level one.
Classes are taught in Dutch. The course material, tools, and exams are in Englishโwhich is also the standard practice in this field. A solid reading proficiency in English is sufficient to get started. A few times a year, we also offer a class taught entirely in Englishโplease contact us for the dates.
You already have a strong foundationโthatโs your biggest advantage. This program builds on your existing knowledge and experience, allowing you to quickly master the material. What we do offer: personalized guidance, small groups, and intensive hands-on labs that directly relate to your day-to-day work. The leap to this level is a big one, but with the right background, itโs very achievable.
The course consists of 50 study hours, spread over 5 intensive days. You can choose between a consecutive week or a staggered scheduleโfor example, 3 blocks of 2 days spread over 3 weeks, including time for reflection and review between sessions. The exact schedule is negotiable.
This course is not suitable if you have no prior experience with DFIR, forensics, or incident response. Without that foundation, the technical content will move too quickly. Not sure if you're ready? Contact usโwe'd be happy to help you decide.
Modern malware uses self-defense techniques that actively manipulate or destroy volatile data. Most training programs teach you how to work with disks and logsโwe teach you whatโs in memory at the moment of the attack. Thatโs the evidence that makes the difference between a complete reconstruction and a blind spot.