Volatile Data
Definition
Any digital information that is lost when power is removed or the system state changes. Examples include RAM contents, CPU register values, active network connections, the ARP cache, and the process table. Volatile data must be collected while the system is running.
- Field
- Digital forensics, incident response
- Definition
- Data lost when power is removed or system state changes
- Examples
- RAM contents, CPU registers, network connections, ARP cache, process table
- Collection window
- Must be captured while the system is still running
- Governing principle
- Order of volatility guides acquisition sequence
Common questions
What is the practical risk of powering off a live system before collecting volatile data?+
Encryption keys held only in memory, active malware processes, open network connections, and unsaved attacker command history are all lost permanently, which can eliminate the strongest evidence of what was actually happening at the time of compromise.
Does collecting volatile data change the system, and does that matter for evidence integrity?+
Yes, any live acquisition tool running on the target system alters memory and process state to some degree. Examiners document this Locard-style interaction, use minimally invasive trusted tools, and record exactly what was run so the alteration is explainable rather than hidden.
Which volatile artifacts are usually prioritised first in the order of volatility?+
CPU registers and cache are collected first because they change fastest, followed by RAM, then network state and running processes, with disk and logs collected later since they persist after shutdown.
Related terms
- Chain of Custody
- The documented chronological record of who collected, handled, transferred, and examined a piece of evidence. For digital evidence, chain of custody includes...
- Live Acquisition
- Forensic data collection performed on a running, powered-on system. Captures volatile data and allows imaging of encrypted volumes while decryption keys are...
- Live Response
- The process of collecting evidence and triage data from a running system without first powering it down. Preserves volatile artefacts that would...
- Memory-Resident Malware
- Malicious code that executes entirely in RAM and writes no files to disk. Fileless malware, PowerShell-based loaders, and certain rootkits fall into...
- Non-Volatile Data
- Data that persists without power, such as files on a hard disk, SSD, or optical media, and data in non-volatile memory chips....
- Preservation Order
- A legal instrument directing a service provider to retain specific data for a defined period pending receipt of a production order or...
- RFC 3227
- Guidelines for Evidence Collection and Archiving, published by the IETF in February 2002. It defines the order of volatility, the documentation requirements...
- Triage
- The structured process of evaluating an alert to determine whether it is a genuine security incident and, if so, what severity level...
- Write Blocker
- A hardware or software device interposed between a digital storage medium and the forensic workstation that prevents any write commands from reaching...
Explained in these topics
- Intake, Scoping and Evidence PreservationData that exists only while a system is powered on and running: RAM contents, running processes, active network connections, open file handles, logged-in sessi...
- Volatile Data and the Order of Volatility