A method for preserving digital evidence of a computer misconduct, the
method including the steps of: prior to the misconduct, installing an
expansion card capable of retrieving and storing a memory image and
register information from a digital electrical computer in which the
expansion card is installed; connecting a switch to regulate the
expansion card from a location other than the computer; at the time of
the misconduct, using the switch to trigger the retrieving and storing of
the memory image and the register information into the expansion card;
and subsequent to the misconduct, extracting the expansion card to
preserve digital evidence of the computer misconduct. This method can be
carried out further by subjecting the memory image and register
information from the expansion card with another computer to forensic
analysis.