- 2026-05-06 –, C1.03.10: lift to level 3 room #10
- 2026-05-06 –, C1.03.10: lift to level 3 room #10
All times in Europe/Luxembourg What happens in memory, stays in memory! In this beginner workshop, we’ll take our first steps into the fascinating world of Linux Memory Forensics 😊. This session will introduce the fundamentals of volatile memory, Linux memory management, with a touch on memory acquisition. We will then discover how to investigate memory artefacts and uncover traces of malicious behaviour through a simulated ransomware attack, from identifying suspicious processes and carving out binaries to recovering encryption keys from memory. We will mostly use the Volatility framework, but this workshop will go beyond a simple command-line tutorial to explore the underlying principles: what are Volatility profiles and why do we need them, what are some interesting artefacts to look for, what to do when there is no command for what we are looking for, where do we even start looking, etc. Anyone who wants to discover digital forensics! This workshop won’t require extensive hacking knowledge, however knowing a bit about Linux will help. A laptop capable of running a virtual machine (or a native Linux environment), and a few gigabytes of free disk space (a memory dump can be quite heavy!). We might do a little bit of Python too! The VM will contain all the tools needed for the workshop. If you choose to use your own Linux environment instead, a setup guide will be provided.Workshop description
Who should attend?
Requirements
BlackHoodie’s Mission
- BlackHoodie is a series of technical trainings aiming to attract more women to the field of cyber security
- Our events are women-only, except if individual organizers state otherwise
- Whether introduction level or advanced, classes are always challenging
- All of our events are free to attend
- We do not exert any preference in education level, occupation or corporate affiliation of attendees
- BlackHoodie is dedicated to serve the community, we aim to integrate, not separate
- BlackHoodie is independent, and cannot be leveraged to promote anything but its own mission
- We seek quality over quantity, in number of classes and attendees
- We also support/encourage attendees to start giving technical trainings thereby providing a platform to build their confidence
Sonia is a Software Engineer with a passion for Digital Forensics and CTFs