Fundamentals of memory
What information does random access memory (RAM) contain? It will give you information about the current running state of the system before you shut it down. It will contain information about any running programs; these could be legitimate processes, and it could contain running malware processes as well. If attackers have compromised the host, the malware may be a resident in the RAM.
You will also find information related to the host’s network connections with other peers. This could be a legitimate use of peer-to-peer file sharing, or it could show a link to the attacker’s host. These connections are breadcrumbs for you to follow. The user could also be sharing illicit images. Again, the connection to other computers will allow you to follow and investigate additional users for the same crime.
If the user is using cloud services, we may never find the data they are creating on the physical disk in the system. Instead, we may only see...