Security professionals are engaged in a consistently evolving battle with hackers. While in days of yore hackers were often targeting system for braggadocio, today's systems are much more integrated and are attractive targets for individuals, competitors and even nation states. In the process of identifying, tracking and prosecuting attackers computer forensics has evolved and become a much more common practice. As attackers methods have been identified and “mitigated,” their tools and techniques have evolved. Where in the past it was not uncommon to find artifacts, accounts and tools on victim computers, modern tools and techniques often avoid placing files on or altering the victims hard drive. In these situations the only indicators of the event may reside only in volatile memory. Should the incident responder follow old forensics practices and not capture Ram crucial evidence of the event could be lost forever. To make matters even more challenging for incident responders, root-kits and anti-forensics tools and techniques may affect the ability to observe events on compromised machines. During this presentation we will discuss the need to establish valid incident response procedures and training programs. We will also look at some common tools and methods to capture and examine volatile data and information.