Section 3.2: Why Memory Forensics? Flashcards
1
Q
Why investigate RAM?
A
Everything runs through it: processes, threads, malware, network sockets, URLs, IP addresses, open files, passwords, caches, clipboards, encryption keys, hard/software configurations, event logs, and registry eyes.
2
Q
Three exclusive things that only exist in memory and does not write on disk I should be aware of.
A
Incognito sessions run here, registry keys, and chat applications.