Volatile Memory Forensics of Tails OS in a Virtualized Environment Academic Article uri icon

Abstract

  • Operating systems focused primarily on privacy, such as Tails, are designed to minimize forensic traceability through the elimination of permanent storage and reliance on a non-persistent execution model. This study examines the availability of forensic traces retained in volatile memory, specifically within the non-persistent, virtualized environment of Tails. A controlled experiment involving normal user activity was conducted, followed by live RAM data acquisition and analysis using FTK Imager, Volatility 3, and keyword-based extraction techniques. The results demonstrate that traces related to file system activity, network communications, software execution, and external device interaction persist in temporary memory. These findings highlight Tails' forensic visibility beyond its documented threat model and underscore the evidentiary value of live memory analysis in privacy-focused operating systems.

Publication Date

  • 2026-03-01