Problem Statement
Explain the difference between live forensics and dead forensics.
Explanation
Live forensics is performed on running systems to capture volatile data like RAM, active connections, or live malware behavior.
Dead forensics works on powered-off systems or forensic images, analyzing disks, logs, and persistent artifacts. Both complement each other for complete analysis.