Canada, BC
(604) 800-9060
TERADRIVEFORENSICS
Glossary

Glossary term

Memory Forensics

Memory forensics is the analysis of a computer's volatile memory (RAM) to recover running processes, network connections, decrypted content, and other artifacts that exist only while the system is powered on.

Memory contents disappear when a system loses power. For matters where the analysis depends on what was running at a specific moment (an active malware infection, a decrypted volume, a logged-in cloud session), memory must be acquired before the system is shut down.

The standard tool for memory analysis is Volatility, an open-source framework that supports Windows, macOS, and Linux memory images. Memory acquisition is performed with tools that read the raw RAM contents into a file, which is then analysed offline.

Common memory forensic findings include malware processes, encryption keys for mounted volumes, browser session data, cloud account tokens, and network connection state.

For Canadian incident response, memory forensics is critical when the matter involves active malware or when the time of compromise must be tied to specific user sessions.

Related terms

Need digital evidence handled defensibly?

Book a confidential consultation. Our team will reach out as soon as possible.