Should an investigator attempt a live-memory capture?¶
Only if they are trained, authorised and equipped to follow an approved live-acquisition procedure. For most first responders, the right contribution is to recognise why memory matters, preserve the visible state and get the right specialist involved quickly.
This is a capability decision, not a test of confidence with computers.
Start with the question memory could answer¶
A live capture may be proportionate when the enquiry depends on information that could disappear with shutdown or process termination.
| Situation | Why memory may matter | Immediate first-response contribution |
|---|---|---|
| An unlocked encrypted computer | Working memory may contain material needed to understand currently accessible encrypted data | Preserve screen, power, applications and account state; escalate urgently |
| Suspected fileless or memory-resident malware | Relevant code and process relationships may be clearest while running | Record alerts, processes, connections and observed behaviour |
| Active remote control | Memory may connect the remote-access process, session and network activity | Preserve banners, session details, time and unexpected changes |
| Unsaved work or temporary credentials | The live session may contain data unavailable in normal storage | Record the application and visible state; avoid closure or logout |
A capture is less useful when nobody can state what volatile question it is intended to answer, or when the operational and safety risk of collection outweighs the likely evidential value.
Why improvisation is a poor trade¶
Running a tool changes memory and creates new system activity. The wrong executable can destabilise the machine, produce an incomplete or unexplained output, contaminate destination media or expose it to malware. A downloaded utility with no controlled provenance leaves difficult questions about method and integrity.
A competent operator, approved tool, controlled destination, defined objective, contemporaneous notes and a method for preserving and validating the output.
The tool, authority, destination or competence is missing; the system is safety-critical; malware risk is unmanaged; or the likely effect on live services is not understood.
Give the specialist a useful handover¶
Record the system, screen, applications, accounts, network connections, alerts, power source, current time and every action already taken. Explain the specific reason memory evidence may matter and any deadline created by battery, remote activity, encryption or continuing harm.
If an approved capture is performed, preserve the method record described in what a live-memory capture is. If it is not performed, record why and what live observations were preserved instead.