© Nihad A. Hassan 2019
Nihad A. HassanDigital Forensics Basicshttps://doi.org/10.1007/978-1-4842-3838-7_5

5. Acquiring Digital Evidence

Nihad A. Hassan1 
(1)
New York, New York, USA
 

How to acquire volatile and nonvolatile memory

The main task of a computer forensics investigator is to acquire and analyze computing devices’ memory images. In a nutshell, a memory image—widely known as a forensic image—is a static snapshot of all or part of the data on a computing devices’ secondary storage (e.g., HDD, SSD), attached storage device (e.g., USB thumb drive, external hard drive, magnetic tape), or RAM memory (when performing live acquisition on running systems). We can think of this image as a container of data, where you can store individual files or ...

Get Digital Forensics Basics: A Practical Guide Using Windows OS now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.