The importance of RAM, the paging file, and cache in DFIR
OSs can use a portion of the hard disk as an extension of RAM. This is referred to as virtual memory and is usually a good idea if a computer or laptop has limited RAM. Although the hard drive is much slower than the RAM, the swap file or paging file on the disk can store files and programs that are being accessed less, leaving the RAM available to store data that is frequently accessed. This process involves the OS swapping pages of data less frequently used and moving data to the dedicated paging file area on the hard drive.
In forensics investigations, the paging file is very important to us. Although not as volatile as RAM itself due to being stored on the hard disk, it is a hidden file in Windows called pagefile.sys
, and should always be inspected using tools of your choice, as this file may reveal passwords for encrypted areas, information from sites visited, documents opened, logged-in users, printed items, and so...