Modern investigations increasingly involve powered-on computers, locked workstations, cloud-connected applications, encrypted storage, and evidence that may exist only temporarily in volatile memory. Traditional disk-based forensic methods remain essential, but they may not capture the full state of a live system or the artifacts needed to understand recent user activity, running applications, network connections, encryption status, or memory-resident evidence.
The RAM Capture & Analysis (RCA) course is an advanced, hands-on digital forensics course designed to give investigators practical options when a case presents technical challenges and the usual forensic approaches may not be enough. Students learn when volatile memory may be valuable, how to document and acquire it in a defensible manner, and how to analyze memory captures using both commercial and open-source tools. The course emphasizes practical decision-making for law enforcement and digital forensic examiners who may encounter live or locked systems during search warrants, consent searches, incident response, or laboratory examinations.
Students are introduced to memory concepts, operating system behavior, volatile data acquisition, remote capture options, memory analysis workflows, and common forensic artifacts that may be recovered from RAM. Topics include running processes, network activity, registry and event data, browser and application artifacts, malware-related indicators, encryption-related artifacts, and the limitations of memory acquisition. The course also discusses legal, procedural, and documentation considerations so students can better explain what was done, why it was done, and what changed on the system during acquisition.
RCA is not presented as a guaranteed method to bypass every locked system or defeat every encryption implementation. Instead, the course is designed to help students recognize opportunities that may otherwise be missed, understand what options may still be available, and make informed, defensible decisions when volatile evidence may affect the outcome of an investigation. The goal is to leave students with a stronger technical foundation, greater confidence in live-system scenarios, and additional investigative tools for cases where they may have otherwise believed there were no remaining options.


