Order of Volatility


The order of volatility influences how digital evidence is gathered in computer/digital forensics.

  • place more urgency on gathering more volatile evidence first

Volatility is the relative permanence of a piece of evidence.

  • more volatile evidence may be lost easily

Order

  1. Network traffic
  2. Memory contents
  3. System and process data
  4. Files
    • temp files such as swap space first
  5. Logs
  6. Archived records