RAM is one of the most valuable evidence sources in DFIR, especially during a live incident. In many investigations, memory can contain evidence that will disappear permanently the moment the computer is powered off or restarted.
Think of RAM as the computer’s live workspace. The hard drive tells you a lot about what happened historically; RAM can tell you what is happening right now.
A simple example: imagine an attacker compromises a Windows workstation using PowerShell and launches a reverse shell entirely in memory. There may be no obvious malware executable on the disk. If the investigator shuts the computer down before collecting RAM, some of the strongest evidence could disappear.
This is why DFIR commonly follows the Order of Volatility:
CPU/register/cache → RAM → active network connections/processes → temporary files → disk → remote logs/backups.
In practice, RAM is usually acquired before shutting down a compromised machine when operational and legal considerations permit. Common memory-forensics tools include Volatility 3, WinPmem, Magnet RAM Capture, FTK Imager, DumpIt, Belkasoft RAM Capturer, and similar trusted acquisition tools.