In many cases, memory analysis can provide access to evidence you can’t obtain through “dead-box” forensics alone. Decrypted data, network activity, chat records, carved files, usernames and passwords, these are just some examples of evidence that may only be found in volatile memory. Attendees will learn how to incorporate memory artifacts into your investigations and see what critical evidence you may be missing.