Hunting the Malware Inside Memory
Course Content
0 / 85 completedFilesystem Structure
Digital Forensics 101
Types of Criminal Investigations
Identifying Files without Extensions
Boot Process and How not to alter Digital Evidence
Creating Bootable Forensics Media
Using Correct Tools in Specific Scenarios and Order of Volatility
Rules for Evidence Acquisition for Digital Forensics Experts
Hashing and Bits Explained
Bit by bit copy of the evidence
Software Write Blocker vs Hardware Write Blocker
Decoding the Object Header
Important Details about the Evidence
Memory Acquisition with winpmem
Full Volatile Memory Acquisition using Magnet
Downloading and Installing Volatility Framework Safest Option
Downloading Infected Malware Samples
What Happened in This 12 Seconds and What did Investigator did wrong (Scena
Installing and Downloading Required Resources for our Level Up
Analyzing our First REAL Malware
The Difference Between Suspicious vs Stable Processes
Getting Closer to Rootkit
Hunting the Malware Inside Memory
Why Registry is so important in evidence acquisition
Registry Acquisition with KAPE
The Power of Powershell and CMD when accessing Registry
Structure of Windows Registry
Windows Registry GOLDMINE
Preparing our Environment for Advanced Windows Forensics
This Function of Windows is not for Security but this is a nightmare for hackers
GUI Alternative for Viewing Prefetch Files on Live System
Diving into Prefetch Goldmine for Executable Evidence
John The Ripper
Open Source Intelligence and Password Cracking
The Password Theory
Hashcat
John The Ripper (Windows, Linux and Mac OS)
John The Ripper Rules
John The Ripper - Part 2
Hashcat - Rules, Wordlist Generation and other
Windows Security and Passwords
Extracting hashes from hives
Win-Extracting Sam, Security and System Saves
Cracking NTLM with John The Ripper
Getting Linux Hashes and Understanding Struct
Cracking Linux hash, SHA256 and yescrypt
Difference Between MSC MTP and PTP and why PTP is not needed for evidence
Easiest way to analyze old USB Devices
Connected USB Devices History and Building a Case Report Like a Detective
What, Why and When's of Packet Analysis
Understanding Layer 1,2,3 - Hubs, Switches and Routers
Traffic Classifications
Difference between hubs and switches and the information they contain
How Packet Analysis works and Network Forensics Work
Why is Wireshark best tool for our topic
Downloading and Installing Wireshark
How To's of Network Sniffing
Installing and Configuring Wireshark and other Tools in Linux
Integrated or External WiFi Adapters
Customizing Wireshark
Merging Packets from Different Devices for Complete Forensics Analysis
Capture Options
Starting with Filters in Wireshark for Searching the Crime we're looking for
Capture Filters
Installing TcpDump and Tshark
Display Filters
Working with Tshark and TCPDump
Address Resolution Protocol
Internet Protocol (IP)in Theory
Structure of TCP
Time to Live and Routing behaviour
Structure of UDP
UDP Packet analysis - DNS Response
Detailed Analysis of TCP Packet
HTTP Packet Structure
HTTP Communication Analysis
Full DHCP Communication Packet Analysis with Wireshark
Packets don't lie
How a Failed Network Scan or DDOS Attack looks like
Analyzing how Port Scans work Wireshark Statistics
Wireshark and Threat Hunting
Why Browser Forensics is a Goldmine for Catching Criminals
Chromium Based Browser Forensics - Extracting User Data and Detailed History
Chromium Based Browser Forensics - Chrome, Opera, Brave and others
Firefox Based Browser Forensics