Memory Forensics in the age of EDR

Have EDRs taken the glory of in-memory investigation? We' ll go through a side by-side comparison of of incident investigation with modern EDR against traditional memory forensics with volatility3.
(And by comparing we mean complimenting the knowledge and arsenal of blue teams to pick the right solution for the right problem. It's isn't really a competition on what is best, NOR a shameless product selling)

Theory is always good but gaining experience is also important!
We aim to start from memory internals 101 and dive into the analysis of a compromised system using volatility3. We showcase why memory forensics remains a solid option in incident response -even in the age of telemetry, and why rightfully considered an art form.

The workshop aims to be more than an RTFM of volatility3 or use-plugin-and-find flags CTF, but rather equip participants with solid knowledge on linking pieces of evidence to fill the jigsaw puzzle of an incident.
Newbie or seasoned, professional or just curious, this session is for you!


The following topics will be covered:
Part 1: Memory structure
- How memory works in Windows systems
- Evidence in memory

Part 2: Memory in DFIR
- Investigation theory
- Introduction to Volatility3
- Differences with EDRs

Part 3: Hands-On workshop
Analysis of windows system
Download the memory image here: <link will be inserted>

It is a BYOD session, so please have the latest version of volatility installed on your machine!
https://github.com/volatilityfoundation/volatility3
The workshop is not a nintendo-forensics class, It is all about how to use it, not install it! :)