This paper begins with cloud forensics background, describing steps involved in cloud forensics investigation.When it comes to cloud forensics volatile data plays crucial role. Many of Cloud Service Providers (CSP) do nothave proper mechanism for preserving volatile memory data. At most they could do is storing the VirtualMachine (VM) instance. But what if the client (tenant) performs some malicious activity and then ends hissubscription? In such case all of his data will be lost. So we propose a mechanism to store volatile data in adedicated common persistent storage which will provide help during Cloud forensic investigation.