{"podcast":{"title":"CyberCode Academy","slug":"cybercode-academy-7578615","podcast_index_feed_id":7578615,"rss_url":"https://www.spreaker.com/show/6790974/episodes/feed","website_url":"https://www.spreaker.com/podcast/cybercode-academy--6790974","image_url":"https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/5f51ccc7b22fdba95149ffa6346f1533.jpg","author":"CyberCode Academy","episode_count":297,"summary":"Welcome to CyberCode Academy — your audio classroom for Programming and Cybersecurity. 🎧 Each course is divided into a series of short, focused episodes that take you from beginner to advanced level — one lesson at a time. From Python and web development to ethical hacking and digital defense, our content transforms complex concepts into simple, engaging audio learning. Study anywhere, anytime — and level up your skills with CyberCode Academy. 🚀 Learn. Code. Secure. You can listen and download our episodes for free on more than 10 different platforms: https://linktr.ee/cybercode_academy","last_synced_at":"2026-07-13T14:17:20.596630+00:00","page_url":"https://stenobird.com/podcast/cybercode-academy-7578615"},"episode":{"title":"Course 36 - Windows Forensics and Tools | Episode 4: From Acquisition to Volatility Analysis","slug":"course-36-windows-forensics-and-tools-episode-4-from-acquisition-to-volatility-analysis","published_at":"2026-06-02T06:00:02+00:00","page_url":"https://stenobird.com/podcast/cybercode-academy-7578615/course-36-windows-forensics-and-tools-episode-4-from-acquisition-to-volatility-analysis","show_page_url":"https://stenobird.com/podcast/cybercode-academy-7578615","url":"https://www.spreaker.com/episode/course-36-windows-forensics-and-tools-episode-4-from-acquisition-to-volatility-analysis--72013631","audio_url":"https://dts.podtrac.com/redirect.mp3/api.spreaker.com/download/episode/72013631/catching_malware_that_hides_in_ram.mp3","summary":"In this lesson, you’ll learn about: memory forensics and RAM analysis1. Why Memory Forensics Matters RAM (volatile memory) is one of the most valuable forensic sources It contains data that disappears after shutdown 🔹 What RAM can reveal Running processes Active network connections Command history Encryption keys Malware behavior in real time 👉 Key Idea: If disk is “history,” RAM is live truth 2. Memory Acquisition (Capturing RAM)🔹 What is memory acquisition? Creating a snapshot of physical RAM for analysis 🔹 Common Tools DumpIt Simple one-click RAM dump tool Used widely in field forensics NotMyFault Forces system crash Generates full kernel memory dump 👉 Key Tradeoff: DumpIt → fast and simple Crash dump → deeper but disruptive 3. Types of Memory Evidence🔹 What investigators look for Process objects Suspicious threads Injected code Hidden malware artifacts 🔹 Why it’s important Malware often exists only in memory Disk analysis alone may miss it 4. Memory Forensic Techniques🔹 String Searching Look for: Passwords URLs Commands API keys 🔹 Process Inspection Identify: Legitimate processes Suspicious or orphaned processes 🔹 Thread Analysis Detect: Code injection Hidden execution paths 5. Deep Analysis with Volatility🔹 What is Volatility? A powerful memory forensics framework for analyzing RAM dumps 🔹 Key Capability Extracts structured evidence from raw memory images 6. Core Volatility Commands🔹 pslist Shows active processes Based on system process list 🔹 psscan Finds hidden or terminated processes Scans memory directly 🔹 psxview Cross-checks multiple process sources Detects rootkits and hidden malware 👉 Key Insight: If a process appears in psscan but not pslist, it may be hidden 7. OS Profiling First step in analysis is identifying: Operating system version Memory structure…","meta_description":"In this lesson, you’ll learn about: memory forensics and RAM analysis1. Why Memory Forensics Matters RAM (volatile memory) is one of the most valuable for…","key_points":[],"chapters":[],"topics":[],"duration_seconds":1330,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/cybercode-academy-7578615/episodes/course-36-windows-forensics-and-tools-episode-4-from-acquisition-to-volatility-analysis/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/cybercode-academy-7578615/course-36-windows-forensics-and-tools-episode-4-from-acquisition-to-volatility-analysis.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}