RAM Memory Forensic Analysis
RAM is a vital source of digital evidence that has been neglected and ignored historically. As our knowledge of digital evidence grew, examiners realized the source of potential digital evidence that existed in RAM. Ultimately, you have an additional multi-gigabyte source of information that needs to be examined and may contain digital artifacts that do not exist in the traditional locations of the system.
In this chapter, we will cover the fundamentals of memory. We will then look at the different sources of memory and learn to capture RAM using RAM capture tools. By the end of this chapter, you will understand the various methods and tools that can process volatile memory.
We’ll be covering the following topics in this chapter:
- Fundamentals of memory
- Random access memory
- Identifying sources of memory
- Capturing RAM
- Exploring RAM analyzing tools