When collecting data for a computer forensic investigation you want to collect the most volatile data first as it will be lost the quickest. The order of volatility shows which data will be lost first.
Order of Volatility
- Memory contents
- Swap files
- Network processes
- System processes
- File system information
- Raw disk blocks
Memory contents, swap files, network processes, and system processes will all be lost when the suspect system is shut down.