What critical data does RAM (volatile memory) analysis reveal that traditional disk forensics cannot?
-
A
Files deleted years before the acquisition
-
B
Running processes, active network connections, encryption keys, and decrypted data in memory
-
C
File system allocation maps and MFT records
-
D
Registry hive files stored on disk