IT Forensics · Linux

Forensic backup of volatile memory (RAM) under Linux – Capturing transient data from a running system

The RAM of a running Linux system contains a great deal of volatile information which is irretrievably lost upon shutdown, including running processes, network connections and, in some cases, unencrypted keys.

Enquire without obligation

A forensically sound backup of the system memory must therefore be carried out whilst the system is still running and requires specialised tools to minimise the impact of the backup process itself on the memory being backed up.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We back up the volatile memory of running Linux systems in a manner that is forensically traceable and analyse the process, network and other runtime information it contains in a structured manner.

Typical areas of application

Backing up volatile data in the event of acute security incidents
Extracting running processes and network connections from a memory dump
Detection of memory-resident malware that operates without files
Extraction of keys stored in plaintext in memory
Incident Response on Linux Systems
Judicial and non-judicial expert reports

This is how a RAM backup works on Linux

Whilst the system is still running, specialised tools are used to create a forensic image of the working memory, with the sequence of backup steps chosen so that particularly volatile data is captured as a priority. The image is then analysed in a structured manner to identify relevant runtime information.

Why is RAM backup relevant in a forensic context?

Certain types of malware deliberately operate exclusively in RAM, without leaving any permanent traces on the hard drive; for this reason, a memory analysis may be the only way to detect them in such cases.

Even cryptographic keys stored in plain text can be retrieved from a recent backup, which may enable access to data sets that would otherwise be encrypted.

Frequently Asked Questions

Why does the RAM backup have to be carried out whilst the system is running?+
Because the contents of the main memory are irretrievably lost when the system is shut down.
Does the backup process itself alter the contents of the memory?+
To a limited extent, this cannot be entirely avoided for technical reasons, which is why specialised tools that cause as little damage as possible are used.
What information can be extracted from a RAM image?+
These include, amongst other things, running processes, open network connections, loaded kernel modules and, in some cases, access data or keys stored in unencrypted form.

LanCologne – Linux Forensics Cologne

Do you require a professional forensic investigation into „forensic backup of volatile memory (RAM) under Linux"? LanCologne can assist you with the legally admissible backup of digital evidence and the traceable analysis of relevant Linux artefacts.

Get in touch now