Digital Forensics
Collecting, preserving, and analyzing digital evidence after a cyber incident.
Term
description · examples · notesCollecting, preserving, and analyzing digital evidence after a cyber incident.
Description
Includes disk, memory, network, and mobile device forensics.
Used to determine cause, scope, and timeline of an incident.
Evidence must satisfy chain of custody for legal proceedings.
Tools include EnCase, FTK, Volatility, and Autopsy.
What people often say
- Forensics is not just for court — it is also used for internal investigations and improving defenses.
- Booting a compromised system without prior imaging can destroy evidence.
Covers / does not cover
Covers
- Disk, memory, and network forensics
- Timeline analysis
- Evidence preservation for legal proceedings
Does not cover
- Attack prevention
- Automated real-time detection
- Response and containment (that is incident response)
Threats
reduces 3Threats it reduces. Select one to open its page.
Techniques
neutralizes 4Techniques it neutralizes. Select one to open its page.