Digital Forensics
The practice of collecting, preserving, and analyzing digital evidence to investigate a security incident or crime.
Digital forensics↗ is the practice of identifying, preserving, and analyzing evidence found on computers, phones, servers, or networks to reconstruct what happened during a security incident, a breach, or a crime. Investigators follow strict procedures to keep evidence intact and legally admissible, from the moment they touch a device to the final report.
After a ransomware↗ attack or a data breach↗, digital forensics helps an organization determine how attackers got in, what they accessed, and when, which shapes both the technical remediation and any legal or regulatory notification requirements that follow.