
Digital Forensics Awareness & Incident Response (including Memory Analysis) 2 Days
When threats no longer leave traces on hard drives… Are you ready to become an advanced cyber investigator?
Today, Fileless Malware attacks and threats that secretly operate within volatile memory (RAM) are causing significant damage to organizations worldwide. If IT teams or incident responders rely solely on traditional shutdown procedures or hard drive analysis, the most critical evidence stored in RAM may disappear forever!
Duration: 2 Days (09:00 – 16:00)
Training Format: Lecture + Hands-on Workshop
Training Materials Provided: Training Software, Forensic Evidence Images (Forensics Image), Mock Investigation Artifacts, Forensic Duplicator Equipment, Forensic Write Blockers (for demonstration), and Acquisition Report Template Samples
Course Overview
This course focuses on developing practical skills and in-depth understanding of Cyber Incident Response alongside Digital Forensics investigations that follow proper procedures and comply with legal requirements. The curriculum covers all phases from incident preparedness, threat detection and analysis, damage containment and mitigation, through to the collection and analysis of digital evidence from multiple sources.
A key highlight of this course is its in-depth coverage of Memory Analysis, an advanced skill that is increasingly essential today. Modern malware and cyber threats often operate entirely within RAM without leaving traces on hard drives (Fileless Malware). Participants will learn how to capture RAM and utilize industry-leading tools to analyze memory images, detect suspicious processes, identify abnormal network connections, and uncover hidden malware activity.
The course combines theoretical instruction with Hands-on Workshops through realistic scenario-based exercises, enabling participants to gain confidence and apply their skills effectively to prevent, identify, investigate, and respond to cyber threats within their organizations.
Key Course Highlights
- Unlock the Secrets Hidden in RAM: Learn the importance and methodology of identifying volatile data and understanding how attackers exploit memory as an attack vector.
Course Objectives
Participants will be able to:
- Understand Cyber Incident Response Processes: Explain incident response phases and lifecycle frameworks according to international standards.
- Understand the importance of RAM memory in forensic investigations.
- Perform RAM capture from live systems correctly and safely.
- Use tools (such as Volatility) to analyze RAM Images and identify abnormal Processes, Network Connections, DLLs, and Code Injection activities.
- Detect and Analyze Malware (Basic Level): Identify traces of malware activity and malicious behavior within operating systems and memory.
Who Should Attend
- Information Security Analysts (Security Analyst / SOC Analyst)
- Cyber Incident Response Team Members (Incident Response Team)
- Digital Forensics Investigators
- Network and System Administrators
- Cybersecurity Consultants
- IT Managers or Legal Professionals involved in cyber investigations
- Internal Auditors and IT Administrators responsible for handling abnormal system incidents
Benefits
- Practical, Real-World Skills: Participants will gain the essential skills and knowledge required to conduct digital forensic investigations on Windows systems for the prevention, identification, and response to cyber threats within their organizations.
- Forensic Training Dataset: A collection of simulated evidence copies and scenario-based investigation artifacts for hands-on practice and skill development.
- Hands-on Experience with Professional Hardware Demonstrations (Hardware Demo): Participants will observe demonstrations of internationally recognized hardware tools used in digital evidence acquisition, providing a clear understanding of real-world forensic processes, including:
- Forensic Duplicator Demonstration: High-speed bit-by-bit imaging devices widely accepted in the digital forensics community for preserving original evidence integrity.
- Hardware Write Blocker & Accessories Demonstration: Devices that prevent modification of original evidence media, along with supporting accessories to ensure evidence integrity and legal admissibility.
- Understanding Professional Investigation Reports: Participants will learn industry-standard digital forensic reporting formats that are professional, easy to understand, and suitable for legal proceedings.
- Certificate of Completion: An official certificate awarded upon successful completion of the training program.
Participant Prerequisites and Requirements
- Basic knowledge of Windows operating systems
- Basic networking knowledge
- Basic information security knowledge

Training Schedule Day 1
09:00 – 10:30
- Introduction & Welcome
- Forensic Acquisitions Concept & Tools
- Hash Values (Digital Fingerprint)
- Exercise
Training Schedule Day 2
09:00 – 10:30
Section 1 – Memory Forensics
- What is Memory Forensics?
- How is Memory Forensics Different from Hard
- Drive Forensics?
- Why Memory Forensics?
Section 2 – Dealing with Live Systems
- Dealing with Live Systems
- Capturing RAM Memory
- Acquisition Tools
10:45 – 12:00
- Cyber Threats & Economic Crime Thailand
- Define Digital Forensics & Its Importance to Organizations
- Legal Consideration, Evidence Handling & Chain of Custody
- Good Practice Guidelines & The Four Principles of Computer Based Evidence
- Exercise: Identifying Sources of Electronic Devices
10:45 – 12:00
Section 2 – (Continued)
- Acquisition Tools
- Capture RAM Memory
- Memory Locations & Analysis Concepts
- Introduction to Volatility
- Identify Rogue Processes (Basic)
13:00 – 14:30
- Persistent Vs Volatile Data
- Dealing with Live Systems & Servers
- Capturing RAM Memory Concepts & Tools
- Exercise
13:00 – 14:30
Section 3 – Analyzing Processes
- Investigating Process Handles & Registry
- Analyze Process DLLs and Handles
- Memory Artifact Timeline Analysis
- Look for Evidence of Code Injection
- Extract Processes and Objects
- Exercise
14:45 – 16:00
- How to Perform Bulk Forensic Imaging
- Exercise
- Preparing an Incident Response Plan
- Q&A
14:45 – 16:00
Section 4 – Memory Forensics Tools & Case Studies
- Memory Forensics Tools
- Exercise
- Memory Forensic Case Studies








