IImportant information contained in acquired memory includes passwords, registry entries, user data, Windows Vista® BitLocker passkeys and executable code that might not be recoverable from the analysis of a dead machine. Until now the investigator would pull-the-plug from the back of the computer and retreat to the lab. What are we missing by just analyzing a "Dead Machine?"
This three day training session includes extensive hands-on labs to train investigators on various tools and methods for collecting RAM from a running machine. 
|