What is your preferred approach for making a full forensic image of your Qubes installation, if you suspect a possible compromise? Thank you.
To be more specific: I am considering using FTK Imager to capture the volatile memory of my PC. Where would I run this (or any other tool) from? dom0 (f if that is possible)? from a USB stick? or perhaps from a second machine? Thank you.