Of the following pieces of digital evidence, which would be collected FIRST from a live system involved in an incident?
Best practices suggest that live response should follow the order of volatility, which means that you want to collect data which is changing the most rapidly. The order of volatility is:
Memory
Swap or page file
Network status and current / recent network connections
Running processes
Open files
Kristal
4 months agoLynette
4 months agoLaura
4 months agoBilli
4 months agoVernell
5 months agoTequila
5 months agoJoesph
5 months agoLashaun
5 months agoLauran
5 months agoRyan
5 months agoArminda
5 months agoAmalia
5 months agoErinn
5 months ago