Digital forensics is the disciplined recovery and investigation of digital evidence — vital after an incident and in legal cases.
Digital Forensics
Recovering and investigating digital evidence.
Tap or hover a part to learn more.
Find the evidence.
Locate the relevant devices and data sources — endpoints, servers, logs, memory, network captures — that may hold evidence of what happened.
Check your understanding
1. What is chain of custody?
2. Why capture memory before disk?
Keep learning
The forensic process
- Identify — locate relevant devices and data sources.
- Preserve — take a forensic image and maintain chain of custody so evidence is admissible and untampered.
- Analyse — examine artefacts (logs, memory, disk, network) to reconstruct what happened.
- Report — document findings clearly and defensibly.
Order of volatility matters — capture the most fleeting data (memory, network state) before it's lost. Evidence integrity (hashing) proves nothing changed. Forensics is the deep-dive that supports Incident Response and feeds threat hunting.
