This document outlines a workshop focused on Linux memory analysis using the Volatility framework, led by Andrew Case. Participants will learn to recover vital runtime information, investigate live CDs, and detect kernel rootkits through practical demonstrations and examples. The workshop emphasizes the importance of memory analysis in digital forensics, particularly in scenarios where traditional disk imaging is unfeasible.