Windows Memory Forensics & Malware Analysis

Whatโ€™s stored in a systemโ€™s memory tells the story that logs and disks leave behind. In this intensive 5-day course, youโ€™ll learn how to perform forensic analysis of Windows memory at the highest level, from acquisition to advanced malware detection.

  • Requirement: experience with DFIR, Windows, Linux, and Python โ€” this is an expert-level track.
  • 50 hours of intensive hands-on training using real malware samples and open-source tools: Volatility, IDA Pro, x64dbg, and YARA.
  • Ready for immediate use in complex memory analysis, insider threats, and advanced incident response.
  • More than half of the course consists of hands-on labs using real and malware-infected memory images.

Upcoming Start Dates

December 2, 2026
Full

Who is this program for?

For DFIR professionals who want to master memory analysis at the level at which modern attackers operate.

CAREER CHANGER

You're conducting forensic investigations but aren't yet analyzing volatile memory. As a result, you're missing evidence that exists only in RAM: active processes, hidden code, and user actions that aren't visible anywhere else.

IT PROFESSIONAL

Youโ€™re handling complex incidents and want to reconstruct the entire attack chain. Memory analysis gives you the missing piece of the puzzleโ€”what was running at the time of the compromise, and how did the attacker hide?

STARTER

You work at a senior level and want to identify and analyze advanced rootkits, anti-forensic techniques, and post-exploit modules. This course will give you the in-depth knowledge you need to track down attackers who deliberately manipulate or destroy volatile data.

What will you learn?

No theory for theory's sake. From day one, you'll work with real malware samples and forensic memory imagesโ€”developed and validated by experts in the security industry.
MEMORY ACQUISITION & VALIDATION

You will learn how to capture memory securely and in a forensically sound mannerโ€”from live triage to complete memory images. You will validate the integrity of acquisitions and understand the inner workings of Windows memory structures: processes, handles, DLLs, and kernel structures.

MALWARE DETECTION IN MEMORY

You track down hidden and malicious code in memory dumps. You detect code injection, hollow process injection, and API hooks; investigate kernel rootkits; and uncover the self-defense techniques used by advanced malware that employs anti-forensic methods.

STATIC & DYNAMIC MALWARE ANALYSIS

You analyze malicious executables statically and dynamically. You inspect PE headers, extract strings, classify malware using YARA, and track C2 communication, persistence methods, and obfuscation techniques. Tools: IDA Pro, x64dbg, YARA, process monitors.

ADVANCED THREAT ANALYSIS

You'll learn how to detect and respond to security incidents in AWS and Azureโ€”from IAM misconfigurations to container security. You'll also use AI tools to write queries faster, summarize incidents, and generate reports that are ready for management.

Structure of the Program

2 modules, 50 hours, 5 days. The course covers everything from practical malware analysis to advanced memory forensics. All topics are practiced extensively using real and malware-infected memory images.
MALWARE ANALYSIS

Youโ€™ll build a solid foundation in malware analysis. Youโ€™ll set up a secure lab environment and perform static and dynamic analysis on real malware samples. Youโ€™ll learn to read assembly code using IDA Pro, analyze malware functionalityโ€”downloaders, droppers, keyloggers, C2 communication, and persistenceโ€”and identify code injection, hooking, and obfuscation. Each section includes demonstrations and hands-on labs using real malware samples. Duration: Days 1โ€“3.

WINDOWS MEMORY FORENSICS

You perform forensic memory analysis at the highest level. You will capture memory images in a forensically sound manner, analyze them using Volatility, and reconstruct what happened on a system: processes, DLLs, network connections, registry keys, and command history. You will detect advanced techniques such as code injection, hollow process injection, API hooks, kernel rootkits, and anti-forensic methods. All components are practiced intensively using real and malware-infected memory images. Duration: Days 4โ€“5.

What should you include on your resume?

Upon completion, you will have the following demonstrable skills:

  • Memory Acquisition and Forensically Sound Validation of Memory Images
  • Windows Memory Internals: Processes, DLLs, Handles, and Kernel Structures
  • Malware Detection in Memory: Code Injection, Hollow Process Injection, API Hooks, and Rootkits
  • Static and Dynamic Malware Analysis: IDA Pro, x64dbg, YARA
  • Advanced Threat Analysis: C2 Identification, Persistence, and Anti-Forensic Techniques
  • Identifying Indicators of Compromise and Translating Them into Incident Response
  • Ready for use in complex DFIR investigations, insider threats, and advanced incident response

Investigators who don't analyze volatile memory are missing out on the most valuable evidence. After this training, that won't be the case anymore.

What do you get in return for your investment?

โ‚ฌโ€” excl. tax
Duration 50 academic hours
Course Load 16โ€“40 hours per week
Class Format online
Location Schiphol-Rijk

Included

Learning StyleHoursDurationDays
A full week32 hours5 days5 days
Staggered Schedule4 p.m.Flexible2โ€“3 half-days per week
  • Developed by security service specialists
  • Hands-on labs with real malware samples and forensic memory images โ€” no simulated environments
  • Personal guidance and coaching throughout the entire program
  • Access to our alumni network โ€” for knowledge sharing and continued growth within the DFIR community

Financing Options

Finance4Learning

With Finance4Learning, you can easily spread out your investment. The application process is quick, and weโ€™re happy to help you work out what fits your situation. Final approval depends on your personal circumstances.

EMPLOYER PAYS

Many employers cover the full cost of the training. We will provide a detailed proposal.

TEAM QUOTE

Open classes for individual employees, or a customized team program. Weโ€™ll put together a well-reasoned proposal.

Upcoming start dates.

December 2, 2026
Full

Frequently Asked Questions

To participate, you must have experience in forensics and incident response, combined with in-depth knowledge of Windows, solid knowledge of Linux, and hands-on experience with Python. This is an expert-level programโ€”not an entry-level one.

Classes are taught in Dutch. The course material, tools, and exams are in Englishโ€”which is also the standard practice in this field. A solid reading proficiency in English is sufficient to get started. A few times a year, we also offer a class taught entirely in Englishโ€”please contact us for the dates.

You already have a strong foundationโ€”thatโ€™s your biggest advantage. This program builds on your existing knowledge and experience, allowing you to quickly master the material. What we do offer: personalized guidance, small groups, and intensive hands-on labs that directly relate to your day-to-day work. The leap to this level is a big one, but with the right background, itโ€™s very achievable.

The course consists of 50 study hours, spread over 5 intensive days. You can choose between a consecutive week or a staggered scheduleโ€”for example, 3 blocks of 2 days spread over 3 weeks, including time for reflection and review between sessions. The exact schedule is negotiable.

This course is not suitable if you have no prior experience with DFIR, forensics, or incident response. Without that foundation, the technical content will move too quickly. Not sure if you're ready? Contact usโ€”we'd be happy to help you decide.

Modern malware uses self-defense techniques that actively manipulate or destroy volatile data. Most training programs teach you how to work with disks and logsโ€”we teach you whatโ€™s in memory at the moment of the attack. Thatโ€™s the evidence that makes the difference between a complete reconstruction and a blind spot.

Ready for the next step?

Schedule a no-obligation consultation or view the start dates.

Windows Memory Forensics & Malware Analysis

Enter your information and we'll contact you within one business day. Together, we'll discuss whether this program is a good fit for your situation. You're not committing to anything yet.

By sharing your details, youโ€™ll receive our monthly newsletter with course start dates and cybersecurity insights. You can unsubscribe at any time.