Page Loader Logo

The International Association of Computer Investigative Specialists

RCA: RAM Capture and Analysis

RCA Course Overview

Modern investigations increasingly involve powered-on computers, locked workstations, cloud-connected applications, encrypted storage, and evidence that may exist only temporarily in volatile memory. Traditional disk-based forensic methods remain essential, but they may not capture the full state of a live system or the artifacts needed to understand recent user activity, running applications, network connections, encryption status, or memory-resident evidence.

The RAM Capture & Analysis (RCA) course is an advanced, hands-on digital forensics course designed to give investigators practical options when a case presents technical challenges and the usual forensic approaches may not be enough. Students learn when volatile memory may be valuable, how to document and acquire it in a defensible manner, and how to analyze memory captures using both commercial and open-source tools. The course emphasizes practical decision-making for law enforcement and digital forensic examiners who may encounter live or locked systems during search warrants, consent searches, incident response, or laboratory examinations.

Students are introduced to memory concepts, operating system behavior, volatile data acquisition, remote capture options, memory analysis workflows, and common forensic artifacts that may be recovered from RAM. Topics include running processes, network activity, registry and event data, browser and application artifacts, malware-related indicators, encryption-related artifacts, and the limitations of memory acquisition. The course also discusses legal, procedural, and documentation considerations so students can better explain what was done, why it was done, and what changed on the system during acquisition.

RCA is not presented as a guaranteed method to bypass every locked system or defeat every encryption implementation. Instead, the course is designed to help students recognize opportunities that may otherwise be missed, understand what options may still be available, and make informed, defensible decisions when volatile evidence may affect the outcome of an investigation. The goal is to leave students with a stronger technical foundation, greater confidence in live-system scenarios, and additional investigative tools for cases where they may have otherwise believed there were no remaining options.

More Details

Students for this class DO NOT receive a laptop to take home but will receive the equipment used during the week as part of the class.

  • Best practices for identifying, documenting, capturing, and preserving volatile memory from live computer systems.
  • Understanding the forensic value of RAM and how volatile memory may contain evidence that is unavailable after a system is powered down.
  • Recognizing situations where RAM capture may provide additional investigative options, especially with powered-on systems, locked workstations, encrypted storage, active user sessions, and cloud-connected applications.
  • Learning foundational memory concepts, including how operating systems use RAM, processes, network activity, registry data, cached information, and other memory-resident artifacts.
  • Utilizing both commercial and open-source tools to capture and analyze memory from Windows systems, with discussion of considerations for other operating systems.
  • Understanding the limitations of RAM acquisition, including memory smear, system changes, tool impact, acquisition failures, modern operating system protections, and the importance of detailed documentation.
  • Conducting hands-on practical exercises to examine RAM captures for running processes, network connections, browser activity, user artifacts, strings, registry information, and other evidence of recent activity.
  • Exploring how memory analysis can support password recovery workflows, encrypted volume investigations, malware review, and other cases where traditional forensic methods may be limited.
  • Introducing remote, enterprise, and virtual-machine memory capture concepts so students are aware of additional options in larger environments, incident response situations, and lab-based scenarios.
  • Developing the ability to explain memory capture and analysis findings, limitations, and investigative value to other examiners, investigators, supervisors, prosecutors, and courts.

Quick Details

Core Competencies / Details

There are four competency areas addressed in the RCA course

  1. Lock Screen Concepts
  2. Capturing RAM Concepts
  3. Analyzing RAM Concepts
  4. Encryption Concepts

Download PDFPlease click here to download the official RCA Core Competencies document which includes details for each core competency.

Apply knowledge towards:

CFCE IACIS Certification

CFCE

Certified Forensic Computer Examiner Program

CAWFE IACIS Certification

CAWFE

Certified Advanced Windows Forensic Examiner

CMDE IACIS Certification

ICMDE

IACIS Certified Mobile Device Examiner

April 27 - May 8, 2026
Orlando, FL
Upcoming events Details of the next event for this course

Where and When is the RCA Course Offered?

IACIS offers the RCA course at multiple locations, accommodating the varied schedules of our professional audience. For course dates and locations, please visit our EVENTS page.

How to Register for this Course

Existing IACIS members, simply log in with your IACIS credentials and go to the PURCHASE TRAINING page to purchase and register for the course.

For non-IACIS members, the membership fee is waived with the purchase of the training course; however, to register for the course you must complete a membership application at the time of purchase. Go to the PURCHASE TRAINING page to purchase and register for the course and complete your membership application.

Skip to content