没有合适的资源?快使用搜索试试~ 我知道了~
首页Advanced Memory Forensics.pdf
资源详情
资源评论
资源推荐


What we’re covering today…
• Increasing demand for memory analysis skills
• Evolution of FOR526 course objectives
• New bootcamp format (0900-1900)
• Annual 2018 Update Additions
• Expansion of Daily Netwars Challenges
• Support from student feedback
• Artifact research & plugin development
• FOR526 tools arsenal

The Need for Memory Analysis Skills,
for all cybersecurity professionals
Challenges: Increasingly Advanced Threat Landscape
• Evasive Memory-Only Malware Variants
• Effective Cleanup Routines of Malicious Code
• Privacy Cleaners, Anti-Forensics, and Data Destruction Tools
• Increased Use of Encryption and Private Browsing Modes
Goals: What you should learn by the end of the course
• Live Memory Analysis and Acquisition
• Windows Memory Structure Analysis
• Code Injection Detection by Various Methods
• Kernel and Usermode Rootkit Behavior Detection
• Hibernation File, Pagefile and Crash Dump Analysis

4

sans.org/for526
剩余44页未读,继续阅读
















安全验证
文档复制为VIP权益,开通VIP直接复制

评论1