: Traditional methods of digital forensics analyze a static disk image--a bitstream copy of a disk created while the system is offline. Recent trends--including greatly increased disk capacity and the proliferation of mission-critical systems requiring continuous uptime--have limited the effectiveness and applicability of this approach. Live forensics gathers data from running systems, providing additional contextual information that is not available in a disk-only forensic analysis. This article describes what information live forensics can gather, how to use that information as evidence, and what information is best obtained by live forensic analysis.