摘要:Redis is a widely used non-relational and in-memory database system. It holds a large amount of information both in memory and file system, which is of great significance to forensic analysis. This paper mainly proposes a forensic analysis method for Redis based on RDB and AOF file. A method of extracting useful information from RDB backup file is proposed based on the data storage mechanism described in this paper. A method of reconstructing the write operation statements from AOF file is also provided. Finally, the method of directly analyzing data from memory is shown. The experimental results demonstrate the effectiveness of our method. Most of the data could be extracted from RDB and AOF file, which provides important information for forensic investigators.