0
1.1kviews
In what situations would collect an image of memory most useful to the investigation?

Subject: Digital Forensics

Topic: Initial response and forensic duplication

Difficulty: Low

1 Answer
0
18views

A memory image is useful in two situations.

First, when malware is primarily memory-resident and leaves little trace evidence on storage.

Second, when attackers use encryption. We’ve gained access to many a password-protected RAR file through the examination of memory images.

Please log in to add an answer.