The Art of Memory Forensics
Our book is cleared for release at the Blackhat USA conference this August. You can preorder hard copies and Kindle editions on Amazon now. Huge thanks to our publisher, Wiley, for allowing us to exceed 900 pages after we initially estimated 650…without raising the price of the book.
Malware and Memory Forensics Training
The training is not just about a single memory forensics tool named Volatility. The training goes in-depth in numerous topics including Windows internals, malware reversing, Windows data structures, how those structures are parsed, and bypassing encryption. I was looking for an in-depth course and I found it with Volatility. It walks you through exploring the Windows internals, the structures, how they can be parsed, and then actually doing it in labs. This layout results in knowing not just how to use tools for memory forensics but understanding what they are doing and what they are suppose to be doing. To top it off, the content is put into context as it relates to Digital Forensics and Incident Response (DFIR). All in all, it was a great training and I highly recommend it to anyone looking to get more memory forensics knowledge and skills.
- June 9th – 13th, London, UK
- October 6th – 10th, Reston, Virginia
- August 25th – 29th, Canberra, Australia
- December 8th – 12th, Austin, Texas
KnTTools / KnTDD Memory Acquisition
We’ve partnered with GMG Systems, Inc. to promote what we believe is the most reliable, robust, and full featured memory acquisition software available. A few important notes accompany this announcement:
- This offer applies to those who participate in our training course. If you are not an alumni or currently registered for an upcoming class, please contact GMG Systems, Inc. directly.
- You must supply either an X.509 certificate or PGP key for encrypted delivery of the software.
- GMG Systems, Inc. reserves the right to refuse orders.
The Volatility Foundation
2014 Volatility Plugin Contest
Volatility 2.4 Release Coming Up
If you’ve been looking forward to the next Volatility release, you’re not alone! We’ve been working on the 2.4 code base and we expect it to be available on or before the date our books starts shipping. There are 30-40 (lost count at this point) new plugins just for Linux and Mac, not to mention some really awesome new capabilities for Windows. In fact, just yesterday we added the ability to extract cached Truecrypt passphrases from Linux memory dumps.