Memory Analysis is the science of using a memory image to determine information about running programs, the operating system, and the overall state of a computer. Because the analysis is highly dependent on the operating system, we have broken it into subpages:
Various types of encryption keys can be extracted during memory analysis. You can use AESKeyFinder to extract 128-bit and 256-bit AES keys and RSAKeyFinder to extract all private and public RSA keys from a memory dump .
- Mariusz Burdach: Finding Digital Evidence In Physical Memory (PDF)
- Paul Movall, Ward Nelson, Shaun Wetzstein: Linux Physical Memory Analysis (PDF)
- Lest We Remember: Cold Boot Attacks on Encryption Keys (PDF)