What is volatile digital evidence?¶
Volatile digital evidence depends on a live or changing state and may disappear through power loss, disconnection, logout, timeout, restart or ordinary system activity.
Volatility takes several forms¶
Computer memory can contain running processes, current network connections, decrypted material and temporary data. An unlocked phone, authenticated browser, open cloud session or unsaved document may remain available only briefly. Network tables, security alerts and provider logs may be overwritten on short cycles.
The label describes risk of loss, not automatic evidential importance. Identify what information exists only in the present state, how quickly it may change and which event would destroy or replace it.
Preserving one feature may endanger another¶
Powering down can prevent remote interference while destroying memory and active sessions. Leaving equipment running can preserve access while exposing it to battery failure, remote deletion or continued modification. Network isolation may contain harm but interrupt services or remove visibility of hostile activity.
Do not respond to volatility by attempting an improvised live capture. Tools and commands used without the necessary competence can change the system, trigger controls or affect other users. Record the visible state externally, protect power where appropriate and obtain timely specialist advice.
Where urgent intervention is necessary, identify the expected evidential cost before acting if time permits, then document what actually changed. The decision should balance volatility with safety, continuing harm, operational need, authority and available support.
Key takeaway
Recognise which evidence relies on the current live state, record that state promptly and make an explicit decision about the risks of both action and delay.