Chapter 1. Live Response
Collecting Volatile Data

Solutions in this chapter:

▪ Live Response
▪ What Data to Collect
▪ Nonvolatile Information
▪ Live-Response Methodologies
Summary
Solutions Fast Track
Frequently Asked Questions

Introduction

Investigators today are increasingly facing situations in which the traditional, widely accepted computer forensic methodology of unplugging the power to a computer and then acquiring a bit-stream image of the system hard drive via a write blocker is, simply, not a viable option. For instance, it is becoming more common for investigators to encounter servers that are critical to business operations and cannot be shut down. Investigators and incident responders are also seeing instances in which the questions they ...

Get Windows Forensic Analysis DVD Toolkit, 2nd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.