Memory Forensics
Definition
The process of acquiring, preserving and analyzing volatile system memory (RAM) from computing devices to recover ephemeral artifacts such as running processes, loaded modules, network connections, credentials in memory, encryption keys and transient forensic evidence that do not persist on non‑volatile storage.