Reader small image

You're reading from  Learn Computer Forensics

Product typeBook
Published inApr 2020
PublisherPackt
ISBN-139781838648176
Edition1st Edition
Concepts
Right arrow
Author (1)
William Oettinger
William Oettinger
author image
William Oettinger

William Oettinger is a veteran technical trainer and investigator. He is a retired police officer with the Las Vegas Metropolitan Police Department and a retired CID agent with the United States Marine Corps. He is a professional with over 20 years of experience in academic, local, military, federal, and international law enforcement organizations, where he acquired his multifaceted experience in IT, digital forensics, security operations, law enforcement, criminal investigations, policy, and procedure development. He has earned an MSc from Tiffin University, Ohio. When not working, he likes to spend time with his wife and his three miniature schnauzers.
Read more about William Oettinger

Right arrow

Summary

In this chapter, you learned about the cornucopia of artifacts you can recover from RAM. You learned about the different tools you can use for the collection process and the tools you can use for analysis. Remember that the tools are always changing with the technology and as new operating systems are released, your primary tool may not collect RAM. Always have a backup plan in case something like that occurs.

You now have the skills to identify and capture RAM in a manner that conforms to best practices. As you analyze the RAM you have captured, you may find artifacts showing the user's activity on the system, such as social media artifacts and recovering passwords or encryption keys.

You may even find information relating to the user's use of email, which will lead us into our next chapter, which is all about email forensics.

lock icon
The rest of the page is locked
Previous PageNext Page
You have been reading a chapter from
Learn Computer Forensics
Published in: Apr 2020Publisher: PacktISBN-13: 9781838648176

Author (1)

author image
William Oettinger

William Oettinger is a veteran technical trainer and investigator. He is a retired police officer with the Las Vegas Metropolitan Police Department and a retired CID agent with the United States Marine Corps. He is a professional with over 20 years of experience in academic, local, military, federal, and international law enforcement organizations, where he acquired his multifaceted experience in IT, digital forensics, security operations, law enforcement, criminal investigations, policy, and procedure development. He has earned an MSc from Tiffin University, Ohio. When not working, he likes to spend time with his wife and his three miniature schnauzers.
Read more about William Oettinger