30 November 2025 to 3 December 2025
Century City Conference Centre
Africa/Johannesburg timezone
PLEASE NOTE: Registrations Have Closed! Contact chpc@csir.co.za for further queries.

Correlating Memory, Persistent, and Runtime Evidence in Redis

2 Dec 2025, 16:30
30m
1/1-10 - Room 10 (Century City Conference Centre)

1/1-10 - Room 10

Century City Conference Centre

50

Speakers

Dr Mary O. Adedayo (Applied Computer Science, The University of Winnipeg) Muhammad Abdul Moiz Zia

Description

Databases are an important source of digital evidence, but most forensic methods and tools are focused on relational database systems. In-memory NoSQL databases, such as Redis are harder to investigate because persistence files and logs record only part of the activity, and volatile evidence exists in memory. This paper presents a technique and parser to bring multiple Redis sources: memory snapshots, RDB, AOF, MONITOR, ACL logs, and SLOWLOG together. Three experiments were carried out. The first tested recovery of short and long values from memory, showing that command arguments can be extracted from an offset even when not preserved in persistence. The second measured coverage across individual sources and demonstrates that combining them gives a broader view of the investigation. The third examine a master-replica scenario, where the parser recovers missing operations by matching memory with monitor logs. Our findings show that cross-source artifact correlation improve completeness in Redis forensic analysis.

Primary author

Muhammad Abdul Moiz Zia

Presentation Materials

There are no materials yet.