Live-Forensik

Live Forensics

Live-Forensik

Live forensics is the investigation of a running, powered-on system in order to secure volatile data that would be lost on shutdown — such as memory, active network connections, running processes and decrypted content. It is indispensable when the decisive traces exist only during operation. Every intervention, however, alters the system slightly.

History & facts. Many modern attacks leave hardly any traces on the data carrier and live in memory — memory-resident malware, decrypted data, active Command and Control (C2) connections. If such a system is shut down, this evidence is lost. Live forensics secures it during operation but accepts in return that every access changes the state minimally. This unavoidable change becomes manageable through a documented, as restrained as possible approach.

Outlook & recommendation. The central trade-off — securing volatile evidence versus not distorting the system — demands a conscious, reasoned and documented decision. In practice, memory is secured first (memory forensics) before further steps follow. Since time is pressing in an emergency, the approach and tools should be prepared — improvised intervention often destroys more traces than it secures.

Live-Forensik — Live Forensics