in spite of the fact that the main point of virtualization is having "containerized" environments for every instanced OS without sharing memory space, are there techniques to make forensics on either online or offline (paused) virtual machines?
Question is biased towards the fact I hope there is no such possibility, but than again, my concern is the fact that, in very layman's terms, when you pause your virtual machine, memory should be "dumped" somewhere on the host in order to restore it later.
Is it possible to access (read only) sensitive information from the VM in that case? If so, are there mitigation procedures for such events and how should they be properly applied?
With my very best,
Bruno