> with keys that are in memory on the same system
I'm not sure that actually holds — the encryption keys are in memory, but the decryption keys don't necessarily have to be.
The pre-encrypted payloads definitely are in memory at some point; however snatching them probably involves larger-scale reverse-engineering.