7

RAM Memory Forensic Analysis

RAM is a vital source of digital evidence that has been neglected and ignored historically. As our knowledge of digital evidence grew, examiners realized the source of potential digital evidence that existed in RAM. Ultimately, you have an additional multi-gigabyte source of information that needs to be examined and may contain digital artifacts that do not exist in the traditional locations of the system.

In this chapter, we will cover the fundamentals of memory. We will then look at the different sources of memory and learn to capture RAM using RAM capture tools. By the end of this chapter, you will understand the various methods and tools that can process volatile memory.

We’ll be covering the following topics ...

Get Learn Computer Forensics - Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.