Memory-Forensik

Memory Forensics

Speicherforensik

Memory forensics is the analysis of a system's volatile memory (RAM). The memory contains traces that exist nowhere else: running and hidden processes, decrypted data, entered passwords, active connections and memory-resident malware. It is often the only way to capture modern, fileless attacks.

History & facts. For a long time forensics concentrated on data carriers; with the advent of fileless attacks that operate exclusively in memory, the analysis of RAM became indispensable. The prerequisite is a memory dump taken during operation. Specialised tools reconstruct from it processes, loaded modules, network connections and injected code — even when the malware tries to hide from the operating system. Outlook & recommendation. Because memory is lost on shutdown, its preservation ranks at the very top of the order of volatility — before the disk image. Those who reflexively switch off a suspicious machine often destroy the most important evidence. Memory forensics is thus a central building block of live forensics and, precisely against advanced, disguised attacks, often the decisive one.
Memory-Forensik — Memory Forensics