When collecting evidence from computers, the policy used to be "power it down, and do dead-drive forensics". Over the last few years, this has shifted to "grab RAM and only then consider powering it down."
Memory contains all sorts of potential evidence, from encryption keys to malware to passwords. Failing to collect this information can significantly hamper or even kill an investigation.
The research into freezing and then extracting RAM contents was interesting, but not terribly practical.
Memory contains all sorts of potential evidence, from encryption keys to malware to passwords. Failing to collect this information can significantly hamper or even kill an investigation.
The research into freezing and then extracting RAM contents was interesting, but not terribly practical.