Summary

In this chapter, we covered issues that are related to volatile data collection. We discussed different tools and approaches to how to collect memory and network traffic.

In the next chapter, we will discuss issues that are related to non-volatile data collection. We will discuss how to duplicate hard drives and how to use standalone tools such as IR CD for this.

Get Practical Windows Forensics now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.