IT Forensics · Linux
Forensic backup of volatile memory (RAM) under Linux – Capturing transient data from a running system
The RAM of a running Linux system contains a great deal of volatile information which is irretrievably lost upon shutdown, including running processes, network connections and, in some cases, unencrypted keys.
A forensically sound backup of the system memory must therefore be carried out whilst the system is still running and requires specialised tools to minimise the impact of the backup process itself on the memory being backed up.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.
Our services
We back up the volatile memory of running Linux systems in a manner that is forensically traceable and analyse the process, network and other runtime information it contains in a structured manner.
Typical areas of application
This is how a RAM backup works on Linux
Whilst the system is still running, specialised tools are used to create a forensic image of the working memory, with the sequence of backup steps chosen so that particularly volatile data is captured as a priority. The image is then analysed in a structured manner to identify relevant runtime information.
Why is RAM backup relevant in a forensic context?
Certain types of malware deliberately operate exclusively in RAM, without leaving any permanent traces on the hard drive; for this reason, a memory analysis may be the only way to detect them in such cases.
Even cryptographic keys stored in plain text can be retrieved from a recent backup, which may enable access to data sets that would otherwise be encrypted.
Frequently Asked Questions
LanCologne – Linux Forensics Cologne
Do you require a professional forensic investigation into „forensic backup of volatile memory (RAM) under Linux"? LanCologne can assist you with the legally admissible backup of digital evidence and the traceable analysis of relevant Linux artefacts.
Related to this topic
- Detecting web shells on Linux-Servern – Forensically identifying malicious Server scripts
- Detecting cryptomining malware on Linux systems – providing forensic evidence of unauthorised resource usage
- Forensic reconstruction of reverse shells – Forensic detection of outbound remote access by attackers
- Forensic analysis of Linux ransomware – reconstructing encryption attacks on Linux systems