Memory can reveal what disk cannot
A great deal of what matters during an intrusion exists only while the machine is running.
Running processes, network connections, decrypted data, credentials, and malware that never touches the disk at all. Turn the machine off and all of it is gone permanently. This is why the instinct to immediately power down a compromised machine, which feels decisive, frequently destroys the only evidence that would have explained anything.
More on Digital forensics
- Forensic copies protect original evidenceMark the copy, never the original
- Hashes can show evidence stayed unchangedThe same short string, twice
- Timestamps need interpretationOne moment, three different times
- Forensic tooling can change the thing examinedYou leave prints of your own
- Deleted does not always mean goneThe card, not the book
- Cloud forensics depends on provider evidenceYou get what comes through the hatch
