Capturing information about the current state of a suspect computer before powering it down is important to a forensic investigation. There is a wealth of volatile data that can be lost once the suspect's computer is powered down. This information may help direct an investigation in the early stages and can be beneficial during other stages of the investigation. First responder triage tools can capture this important data which can play a critical roll in every investigation.
Important information that may be lost when the computer is powered down may include:
- Clipboard contents
- Attached device listings
- Open network ports
- Current running applications and processes
- Temporary cache files
- Active memory contents
- Connected network drives
- Active peer-to-peer connections
- And more...