Introduction to Memory Analysis with Rekall
*(ISC)² Members/Associates can access this course for free by logging in above and clicking the 'My Courses' menu item.
Analyzing a suspect system "live", before disconnecting it and imaging the disks, often yields valuable forensic evidence. Further, it can help you determine whether a crime has been committed at all, or whether the system contains evidence at all, thereby avoiding time-consuming examination of irrelevant machines. Rekall is an advanced, open-source memory capture and analysis framework that has expanded to include a variety of live incident response tools. This Hands-On Lab course will introduce you to the Rekall framework, both for extracting evidence from memory images and for analyzing the current live state of the system. You will learn about several Rekall tools, both on the command line and via the interactive console, for analyzing memory images. You will then analyze several images of Windows systems with in-memory malware.
This course includes the following five (5) labs: 1) Using Rekall on the Command Line 2) Rekall Interactive on a Live System 3) Malware Analysis: Zeus 4) Malware Analysis: Tigger 5) Malware Analysis: Coreflood
Audience or Who Should Take This Course
Experienced cyber, information, software and infrastructure security professionals who want to learn how to extract evidence from memory images and analyze the current live state of the system using the Rekall framework.
Familiarity with security concepts.
How This Course Works
Lab content within this course take place within a Windows 10 64bit virtual machine. Before each lab topic, you will be asked to watch an instructional video that will guide you through the content and review the necessary background information to complete the lab assignment. There is no time restriction, but this lab will take approximately two hours to complete. The exercises are intended to be completed in sequential order, and all elements within the lab are required to complete the course.
At the end of the course, you will be asked to take a final assessment. Please note that you must score 70% or higher on the final assessment and complete the course evaluation prior to receiving a certificate of completion and earning (2) continuing professional education (CPE) credits.
Please make sure at the end of the course that you download and retain the certificate of completion as proof of credits earned. CPEs earned for this course may be eligible for continuing professional education credits for non-(ISC)² certifications. Please visit the continuing education requirements established by the credentialing organization for eligibility.