1
00:00:06,510 --> 00:00:08,280
- In this segment, we're gonna take a look

2
00:00:08,280 --> 00:00:10,440
at the importance of RAM capture.

3
00:00:10,440 --> 00:00:13,200
Now, you might notice
some 2020 file dates.

4
00:00:13,200 --> 00:00:14,730
In this lesson, this is a lab

5
00:00:14,730 --> 00:00:17,580
I created for the SYO 601 course

6
00:00:17,580 --> 00:00:20,130
and I liked it so much
that we're reusing it.

7
00:00:20,130 --> 00:00:23,640
And it still is relevant
today, as it was then.

8
00:00:23,640 --> 00:00:26,040
All I do at that point is click capture

9
00:00:26,040 --> 00:00:28,680
and it's going to capture all of the RAM

10
00:00:28,680 --> 00:00:30,390
and it's going to put it into a file

11
00:00:30,390 --> 00:00:33,750
that has a dot m e m extension.

12
00:00:33,750 --> 00:00:36,090
Now to save time, I've
already taken care of that

13
00:00:36,090 --> 00:00:38,850
and done that. So then what do we do next?

14
00:00:38,850 --> 00:00:40,383
Well, let's close that up.

15
00:00:41,280 --> 00:00:42,390
The next thing we have to do,

16
00:00:42,390 --> 00:00:44,700
is we have to import that file

17
00:00:44,700 --> 00:00:48,180
into a Evidence analysis program.

18
00:00:48,180 --> 00:00:49,920
I happen to be using Evidence Center.

19
00:00:49,920 --> 00:00:51,753
Again, this is a Belkasoft program.

20
00:00:52,890 --> 00:00:56,280
To import the data, I just could go

21
00:00:56,280 --> 00:00:59,070
into a data source and it says,

22
00:00:59,070 --> 00:01:00,150
what's your data source?

23
00:01:00,150 --> 00:01:02,790
Are you importing data from the cloud?

24
00:01:02,790 --> 00:01:06,750
From a drive? From a mobile device?

25
00:01:06,750 --> 00:01:10,050
Or coming up here from a RAM image?

26
00:01:10,050 --> 00:01:11,760
And there is the full path

27
00:01:11,760 --> 00:01:14,670
to the RAM memory image
file that I created.

28
00:01:14,670 --> 00:01:16,980
I've already brought
that into Evidence center

29
00:01:16,980 --> 00:01:20,430
and had it do its analysis,
looking for artifacts.

30
00:01:20,430 --> 00:01:22,833
Because it takes quite a while to do that.

31
00:01:24,510 --> 00:01:29,510
So what was the output? Well,
here's what's really amazing.

32
00:01:29,730 --> 00:01:31,470
Right? I have a predefined search.

33
00:01:31,470 --> 00:01:33,900
It says, look for Windows full
path, look for phone numbers,

34
00:01:33,900 --> 00:01:38,040
postal codes, URLs, payment
card numbers, IP addresses,

35
00:01:38,040 --> 00:01:41,283
email addresses or search engine results.

36
00:01:44,040 --> 00:01:49,040
And a total of 3,026 artifacts
were identified in RAM.

37
00:01:49,620 --> 00:01:53,280
Now, the majority of
them are pictures, 1,381.

38
00:01:53,280 --> 00:01:56,880
But then Internet Explorer
links, Chrome links,

39
00:01:56,880 --> 00:01:59,103
link files, and then others.

40
00:02:00,060 --> 00:02:04,293
So contacts and various
types of artifacts.

41
00:02:07,830 --> 00:02:09,900
I wanna get an overview, again,

42
00:02:09,900 --> 00:02:12,630
I can look at what all of those files are,

43
00:02:12,630 --> 00:02:16,233
whether it's jump lists
or perhaps it's pictures,

44
00:02:17,520 --> 00:02:19,740
chats that I may have had. Right?

45
00:02:19,740 --> 00:02:22,770
They're all gonna be
showing up right here.

46
00:02:22,770 --> 00:02:24,540
I can also get a timeline

47
00:02:24,540 --> 00:02:26,670
of all of the activity that happened.

48
00:02:26,670 --> 00:02:27,930
That's being collected, you know,

49
00:02:27,930 --> 00:02:30,123
that was being extracted from RAM.

50
00:02:31,620 --> 00:02:34,500
As well as just additional information

51
00:02:34,500 --> 00:02:35,610
about all of the data.

52
00:02:35,610 --> 00:02:37,470
But again, just thinking about this.

53
00:02:37,470 --> 00:02:39,060
This is the information that's in RAM,

54
00:02:39,060 --> 00:02:41,220
the pictures, the jump lists, the mails,

55
00:02:41,220 --> 00:02:44,280
the chats, the URLs, contacts, documents.

56
00:02:44,280 --> 00:02:47,580
Now of course, I'd also be
doing forensics on the drive

57
00:02:47,580 --> 00:02:49,800
but this is gonna give me a snapshot

58
00:02:49,800 --> 00:02:53,010
of what was happening as close
to the incident as possible,

59
00:02:53,010 --> 00:02:54,810
which is why it's really important

60
00:02:54,810 --> 00:02:57,720
to collect evidence
quickly and to make sure

61
00:02:57,720 --> 00:03:00,360
that you collect all the evidence you can

62
00:03:00,360 --> 00:03:04,350
in a forensically sound,
non contaminated manner.

63
00:03:04,350 --> 00:03:07,590
So that then you can
actually use that information

64
00:03:07,590 --> 00:03:11,700
to do your analysis, and
ultimately to build a case

65
00:03:11,700 --> 00:03:13,383
that will be accepted in court.

66
00:03:14,550 --> 00:03:19,140
You know, forensics is such an
incredibly fascinating field.

67
00:03:19,140 --> 00:03:20,850
It's absolutely, it's one of my favorites.

68
00:03:20,850 --> 00:03:24,330
So, you know, as you're
pondering your career path

69
00:03:24,330 --> 00:03:28,770
this is one that I absolutely
encourage you to explore.

70
00:03:28,770 --> 00:03:31,923
And that my friends is a
closer look at RAM capture.
