IWM — Investigating Windows Memory
13Cubed's Windows memory forensics certification covering Volatility 2/3 and MemProcFS in significantly more depth than SANS FOR508. Topics include process enumeration, code injection detection (basic, reflective DLL injection, process hollowing), API and SSDT hooks, kernel module analysis, YARA scanning, malware memory analysis, and an introduction to WinDbg crash dump analysis. Seven memory images provided for hands-on practice. GCFA holders have noted IWM covers memory forensics tools more thoroughly than the corresponding FOR508 content. Same non-proctored open-book assessment format as IWE with 40% practical weight. Community consensus is this is the best affordable memory forensics training available.
| Issuer | 13Cubed |
| Level | intermediate |
| Domains | Digital Forensics & Incident Response |
| Practical weight | 50% |
| Cost (USD) | 795 |
| Renewal | Never expires |
| Skills | memory_forensics, windows_memory_forensics, malware_behavior_analysis, malware_triage, ioc_extraction |
Official certification page
Browse all 426 cybersecurity certifications on EBCertMap