Physical Memory Image
Definition
A byte-for-byte copy of all installed RAM on a running system, acquired at the hardware or kernel level. Contains all data structures, process content, and kernel objects present in memory at the moment of capture.
- Content
- Byte-for-byte copy of installed RAM
- Acquisition level
- Hardware or kernel level
- Captures
- Process content and kernel objects at capture moment
- Field
- Digital forensics, incident response
Common questions
Why is a physical memory image considered more volatile than a disk image?+
RAM contents change continuously and are lost entirely when the system loses power, so a memory image only reflects one instant in a constantly shifting state. Because of this, memory acquisition is normally prioritised early in incident response, before any action that might require a reboot or shutdown.
What can a physical memory image reveal that a disk image cannot?+
It can capture running processes, open network connections, encryption keys held in memory, and malware that exists only in RAM without ever writing itself to disk, none of which would appear in a static disk image taken after the fact.
Related terms
- LiME (Linux Memory Extractor)
- A loadable kernel module that acquires physical memory from Linux, macOS, and Android systems. It maps the physical address space and either...
- Order of Volatility
- The sequence in which digital evidence should be collected, ranked from most to least transient. Defined in RFC 3227. CPU registers and...
- Process Injection
- A technique used by malware and attackers to execute code inside the address space of a legitimate running process. Common methods include...
- Reflective DLL Loading
- A technique that loads a Windows DLL directly from memory without registering it with the OS loader. The DLL resolves its own...
- Volatility Framework
- An open-source memory forensics framework written in Python. It parses raw memory images using OS-specific symbol information to reconstruct kernel data structures...