Skip to content
Skip to main content
First Response & Preservation Technical Explainer

What is a live-memory capture?

A live-memory capture is a specialist acquisition of data from a computer's working memory while the system is still running.

It produces an examination file for later analysis. It is not a screenshot, a normal file copy or a perfect freeze of one instant.

The capture happens while memory is changing

A capture tool reads available memory and writes the result to controlled destination storage. During that interval, the operating system, applications and capture tool continue to run.

BaselineRecord the live systemScreen, users, applications, time, network, power and reason for capture.
AcquisitionTool reads working memoryThe tool itself creates processes and the system continues to change.
OutputCapture written to controlled mediaRecord tool, version, destination, start/finish and errors.
ExaminationSpecialist interprets the imageFindings are compared with disk, endpoint, network and provider records.

The resulting image may contain processes, connections, sessions, temporary credentials, decrypted content and other volatile evidence. Its exact content depends on the machine, operating system, capture method and what changed during collection.

The collection record is part of the evidence

A useful capture should be accompanied by:

  • the computer and state from which it came;
  • the question that justified live acquisition;
  • operator and authority;
  • tool and version;
  • start and finish times with time zone;
  • destination media and output file;
  • recorded integrity value where the procedure produces one;
  • warnings, failures and incomplete regions; and
  • known changes caused by the acquisition.

That record allows an examiner to distinguish the captured system from collection activity and explain why the output is reliable enough for its intended use.

What the result can establish

A memory capture can show that a process, connection, session or data fragment was present during the collection interval. It can join items that would otherwise appear in separate logs. It cannot recreate state that had already disappeared, and a fragment found in memory does not automatically prove who created it or why.

The capture therefore complements disk, endpoint, network and provider evidence. It does not replace them. Interpret the image alongside its acquisition record and those other sources.

Reference: FRP-084First Response & Preservation