Modern intrusions increasingly avoid the disk entirely, which makes memory the only place the evidence exists. This course covers acquisition with tools such as WinPmem and LiME, then analysis in Volatility: listing processes including hidden ones, recovering network connections, extracting injected code, and pulling credentials and encryption keys from memory. Malware analysis begins with safe lab construction and isolation, then static triage through strings, imports, and packing detection, followed by dynamic analysis of process, file, registry, and network behaviour. You will work through fileless techniques, process injection and hollowing, and persistence mechanisms. Each exercise ends with indicators of compromise written up for a detection team.