What evidence may exist only in memory?¶
Some digital evidence may exist only in a computer’s live memory and disappear when power is lost.
Why this matters¶
The dangerous assumption is that all important evidence is stored permanently on the drive. Running systems hold temporary information that may never be written to storage.
What to record and do¶
Memory may contain running processes, active network connections, encryption keys, logged-in sessions, temporary credentials, clipboard contents and unsaved data.
It may also contain evidence of malware, remote access, command activity and recently used applications.
Powering off, restarting or allowing the system to crash may remove that evidence.
Before changing power state, record the screen, open applications, network connections and visible activity.
Do not attempt a memory capture unless trained, authorised and equipped to do so. Improvised collection can alter or contaminate the system.
Where memory evidence may matter, seek specialist support urgently.
A specialist may need to balance live capture against containment, safety and business continuity.
If power is lost before specialist action, document the time and circumstances honestly.
Live memory may also reveal which user accounts are active, what devices are connected and what data has recently been handled. It can help explain the state of the system at that moment, but it is highly changeable and any collection will itself affect it.
Memory evidence is especially important where malware, encryption or remote access is suspected.
Where specialist capture is undertaken, record the tool, operator, time and any known effect on the running system.
Operational takeaway¶
Recognise that memory can hold unique live evidence, and obtain specialist support before shutdown, restart or improvised acquisition.