Tech Fixx · Video
RAM Forensics for Beginners: Capture & Analyse Volatile Memory | Part 11
Watch this 3 min 26 sec tutorial from the Tech Fixx channel, published .
Check that the device, software and version shown match your setup. Use the player controls for captions, playback speed and full screen where available.
Loading the player connects to YouTube. If playback is unavailable here, watch on YouTube ↗.
From the video description
Volatile memory can contain running processes, network connections, encryption material and other evidence that disappears when power is removed. Part 11 of this digital-forensics course explains the purpose and workflow of RAM acquisition and analysis.
You’ll learn: • Why memory evidence is time-sensitive • How to plan an authorised live acquisition • Recording system state, time and tool details • Creating and hashing a memory image • Identifying processes and network artifacts • Preserving the original capture and working from copies • Limits and contamination risks in live response
Chapters: 0:00 The Volatile Memory Secret 1:45 What Threat Actors May Hide in RAM 3:30 Tools for Capturing Memory 6:15 RAM Analysis Workflow 9:50 Malware-Hunting Example 12:20 Incident-Response Tips
Use only on systems you are authorised to examine and follow your incident-response procedures.
#MemoryForensics #RAMAnalysis #DigitalForensics