Identifying sources of memory
What happens if you are not the investigator on the scene when the digital evidence is collected in the RAM, and they do not collect volatile data? Is it possible to still access the RAM, despite having the system shut down? While you cannot analyze the RAM, it is possible to examine other sources may contain the same data that was stored in the RAM. This option may not always be viable, depending on the specific set of circumstances surrounding the seizure of the digital evidence.
You need to know that there are potential additional sources that will contain the same or similar data that was in RAM. They are as follows:
- Hibernation file (hiberfill.sys): Hibernation is the process of powering down the computer while still maintaining the current state of the system. In Windows, the RAM is compressed and stored in a
hiberfill.sys
file. This will allow the system to power down completely, but when the system is reactivated, the contents of the...