Live versus post-mortem acquisition
In this section, we’ll look at the different procedures for live and post-mortem evidence acquisition. However, before we begin, first, we must understand the order of volatility.
Order of volatility
When collecting evidence, we should keep in mind the volatility of data. As mentioned earlier in this chapter, data can be easily lost or destroyed. As such, when collecting data, a well-documented and common best practice is to collect evidence in the order of most volatile to the least volatile if possible.
The Scientific Working Group on Digital Evidence (SWGDE) capture live systems document and lists the order of volatility from most to least volatile and crucial, as follows:
- RAM
- Running processes
- Active network connections
- System settings
- Storage media
Powered-on versus powered-off device acquisition
When investigating devices that are powered on and powered off, special consideration must be given...