Skip to content

Live Incident Response: Volatile Memory Acquisition and Triage

Volatile memory can contain process state, loaded code, network details, and other data that may disappear when a host is shut down. A memory capture is a point-in-time acquisition: it changes the live system, can miss inaccessible pages, and may be affected by the acquisition tool and operating system.

Use your incident plan to decide what to collect and in what order. RFC 3227 recommends collecting evidence from more volatile to less volatile and gives a typical example; it does not replace incident-specific safety, containment, or evidence-handling decisions.

Workflow from approved live memory acquisition to hashing and protected evidence storage

Memory acquisition workflow: capture to a writable case destination, calculate a hash after the capture, record it with the case notes, then protect the evidence copy.



Step 1: Record the Host and Prepare a Writable Destination

01

Document the System and Check Case Storage

Preparation

Use trusted, pre-positioned acquisition tools where possible. Keep the tool media separate from the evidence destination. The destination must be writable during capture and have enough free space for the memory image, notes, and hash manifest. After acquisition and verification, protect the evidence copy according to your process.

Terminal window
$CaseDir = 'E:\DFIR_Case_001'
New-Item -ItemType Directory -Path $CaseDir -Force | Out-Null
$os = Get-CimInstance Win32_OperatingSystem
[pscustomobject]@{
CapturedUTC = [DateTime]::UtcNow.ToString('o')
Hostname = $env:COMPUTERNAME
OS = $os.Caption
Architecture = $os.OSArchitecture
RAM_GiB = [math]::Round($os.TotalVisibleMemorySize / 1MB, 2)
}
Get-Volume -DriveLetter E |
Select-Object DriveLetter, SizeRemaining, FileSystemType
❯ View Expected Console Output
Confirm before continuing:
- Host name, OS, architecture, and UTC collection time recorded
- Case destination is writable and has sufficient free space
- Case ID and evidence handling owner are documented

Step 2: Acquire Memory with an Approved Tool

02

Capture the Live Memory Image

Acquisition

Run only the command for the tool version you have validated. The Windows example uses the WinPmem mini executable’s documented positional output path. Linux examples use Microsoft’s AVML or a LiME kernel module prepared for the running kernel. Prepare LiME on a trusted matching build system before an incident; do not install compilers or build the module on the suspected host.

Terminal window
# Run from an elevated PowerShell session with the approved tool available.
$Tool = 'E:\IR-Tools\winpmem_mini_x64.exe'
$Image = 'E:\DFIR_Case_001\WORKSTATION-04-memory.raw'
& $Tool $Image
# Confirm that a non-empty output file was created.
Get-Item -LiteralPath $Image |
Select-Object Name, Length, LastWriteTimeUtc
❯ View Expected Console Output
Verify the tool reports completion, the destination file exists, and its size is plausible for the host.
Record the exact tool version, command, start/end times, errors, and output path.

Step 3: Hash the Completed Image and Record Custody

03

Calculate SHA-256 After the Capture Completes

Integrity

Hash the completed image and store the hash in the case record. A SHA-256 hash helps detect later changes; it is not a digital signature and does not by itself prove who collected the file or that the acquisition was complete. Keep the notes and manifest with the case, and restrict write access to the evidence copy after verification.

Terminal window
$Image = 'E:\DFIR_Case_001\WORKSTATION-04-memory.raw'
$Hash = Get-FileHash -LiteralPath $Image -Algorithm SHA256
$Manifest = [pscustomobject]@{
CaseID = 'INC-2026-1005'
SourceHost = $env:COMPUTERNAME
CapturedFile = (Get-Item -LiteralPath $Image).Name
FileSizeBytes = (Get-Item -LiteralPath $Image).Length
Algorithm = 'SHA256'
Hash = $Hash.Hash
HashedUTC = [DateTime]::UtcNow.ToString('o')
}
$Manifest | Format-List |
Out-File -LiteralPath 'E:\DFIR_Case_001\manifest.txt' -Encoding utf8
$Manifest
❯ View Expected Console Output
Record the actual 64-character SHA-256 value printed for this image.
Compare the file size and hash with the case manifest before moving or analyzing it.

Step 4: Triage the Image on an Analysis Workstation

04

Start Offline Analysis with Volatility 3

Triage

Analyze a verified working copy on a separate, trusted workstation. Do not run string searches or memory-analysis tools on the suspected endpoint as part of this step. Start with system and process context, then investigate network artifacts and suspicious processes. Plugin availability and symbol requirements vary by operating system and image format.

Terminal window
# Run these commands on the analysis workstation with Volatility 3 installed.
vol -f 'D:\Cases\INC-2026-1005\WORKSTATION-04-memory.raw' windows.info
vol -f 'D:\Cases\INC-2026-1005\WORKSTATION-04-memory.raw' windows.pslist
vol -f 'D:\Cases\INC-2026-1005\WORKSTATION-04-memory.raw' windows.netscan
❯ View Expected Console Output
Save the tool version, command lines, plugin output, and any symbol or parsing errors in the case notes.
Treat extracted strings, addresses, and process names as leads to validate, not confirmed indicators by themselves.

Tool references

Comments