The training focused on the examination of digital evidence on the Windows operating system, memory analysis, or RAM Analysis, and the proper process of collecting digital evidence in accordance with computer forensic principles.

Windows & Memory Forensics Course Training Highlights 23/09/2026
Learning Digital Forensics Through Theory and Practice
Throughout the training, participants learned both the theoretical and practical aspects of Digital Forensics, focusing on the proper collection, preservation, and examination of digital evidence in accordance with computer forensic principles.
The content also covered Memory Forensics techniques used to examine data from system memory to support cybersecurity incident investigations, Malware examination, and Ransomware incident analysis.
Key Topics in the Windows and Memory Forensics Training
- Forensic Acquisition: The proper collection of evidence from computers while preserving the condition of the evidence
- Windows Artifacts: The analysis of usage traces and important data on the Windows operating system
- Digital Forensic Reports: Examples of digital evidence collection and examination reports
- Memory Forensics: Principles of memory analysis and the differences from Hard Drive Forensics
- RAM Acquisition: Techniques for acquiring data from memory
- Memory Artifacts: The analysis of Processes, DLLs, Registry, and important data within memory
- Malware and Ransomware Analysis: Case studies involving the examination of malware and ransomware using data from memory
Morning Session: Digital Evidence Collection
During the morning session, participants observed a demonstration of equipment and procedures for collecting evidence from computers in accordance with proper Digital Forensics practices.
Afternoon Session: Mobile Forensics and Ransomware Response
During the afternoon session, there was a demonstration of Mobile Forensics tools, along with an exchange of approaches for responding to Ransomware threats and investigating cybersecurity incidents.
Related Topics: Windows Forensics, Memory Forensics, Digital Forensics, RAM Analysis, Cyber Investigation, Incident Response, Mobile Forensics, Ransomware, Digital Evidence, and DFIR











