Section 3.2: Why Memory Forensics? Flashcards

1
Q

Why investigate RAM?

A

Everything runs through it: processes, threads, malware, network sockets, URLs, IP addresses, open files, passwords, caches, clipboards, encryption keys, hard/software configurations, event logs, and registry eyes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Three exclusive things that only exist in memory and does not write on disk I should be aware of.

A

Incognito sessions run here, registry keys, and chat applications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly