VIII. CONCLUSION
It can be conclude that Live data forensics and therefore RAM
data analysis should become a part of regular forensic
procedures. During every computer analysis (in case the
situation allows it) it is necessary to acquire RAM. The
acquisition itself takes much less time than the acquisition of
other types of memories and the possibility that it contains
information important for the case which would otherwise be
unavailable, is very high. Even though the procedure itself,
the methodology and analysis are neither sufficiently
examined nor documented, the potential results always make
up for it. As described in this paper, the data that can be found
in the RAM can sometimes contain enough evidence to solve
the whole case. Special attention should be given to the fact
that, even though there are deficiencies in the methodology,
there are ways of preventing forensics analysis (the so-called
anti-forensics) and therefore, while performing RAM dump,
attention should be paid to anti-forensic tools.