One of the most basic skills the forensic investigator must master is the acquisition of data in a forensically sound manner. If data is not captured in a forensically sound manner, it may not be admissible in court. In my Kali Forensics series, I showed you how to acquire a forensically sound, bit-by-bit image of a storage device such as a hard drive or flash drive, but now let’s dive into live memory.

Why Capture Live Memory?

In some cases, the forensic investigator will need to grab an image of the live memory. Remember, RAM is volatile and once the… more

