Investigate Cyber Incidents
Digital forensics is the process of collecting, analyzing, and preserving digital evidence from systems.
Computer Forensics → Files & systems Network Forensics → Traffic analysis Mobile Forensics → Smartphones Cloud Forensics → Cloud data
Identify → Collect → Analyze → Report
Logs Files Emails Network data
Autopsy → Disk analysis FTK → Forensic toolkit Wireshark → Network data Volatility → Memory analysis
Integrity → No data change Chain of custody → Track evidence Documentation → Proper records