I recently wrote on my personal blog about some of the new updates to the SANS Forensics 508 course and included a link to a new memory forensics cheat sheet. By popular request, I am posting a PDF version of the cheat sheet here on the SANS blog. Feedback is appreciated!
![CheatSheet.jpg](https://images.contentstack.io/v3/assets/blt36c2e63521272fdc/blt6408d354624d901e/5e4c4ef35fc84a32172f9fa2/CheatSheet.jpg)
Chad Tilbury, GCFA, has spent over twelve years conducting computer crime investigations ranging from hacking to espionage to multi-million dollar fraud cases. He teaches FOR408 Windows Forensics and FOR508 Advanced Computer Forensic Analysis and Incident Response for the SANS Institute. Find him on Twitter @chadtilbury or at http://forensicmethods.com.