Skip to content
FRP-084 Fraud & Financial Crime

What is a live-memory capture?

A live-memory capture is the controlled collection of data held in a computer’s active memory while the system is running.

Why this matters

The dangerous assumption is that memory capture is simply another form of copying files. Memory is highly volatile, constantly changing and closely linked to the current state of the operating system, applications and network activity.

What to record and do

A live-memory capture may preserve running processes, active network connections, logged-in sessions, temporary credentials, encryption material, clipboard contents, unsaved data and evidence of malware or remote access.

That evidence may disappear when the computer is powered off, restarted or crashes.

The capture process itself changes the system. A tool must be introduced or executed, memory will continue changing during collection and new records may be created.

For that reason, memory capture is not an ordinary first-response task for an untrained investigator.

Before any specialist action, record the screen, open applications, visible accounts, network state, power, time and current activity.

A specialist should assess whether memory capture is proportionate, technically feasible and safe in the operational context.

They should also consider encryption, malware risk, business continuity and whether the system is connected to critical services.

If a capture is undertaken, record the operator, tool, version, time, destination media and any known effect on the system.

Do not overstate the result. A memory image reflects a changing live state and still requires specialist interpretation.

Operational takeaway

Treat live-memory capture as a specialist acquisition of volatile system state, not a routine copy, and preserve the visible context before it begins.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.