Live Forensics

Noun · Security & Infosec

Definitions

  1. Forensic collection and analysis performed on a running system before it is powered down or reimaged, often to capture volatile evidence such as memory, active connections, or running processes. Live forensics is valuable when shutting down would destroy important evidence, but it must be done carefully because interacting with the system changes it.

    In plain English: Investigating a system while it is still running so volatile evidence is not lost.

    Example: "The responder chose live forensics first because the malware was fileless and most of the evidence would vanish on reboot."

Related Terms