Systematic investigation and analysis of digital evidence following security incidents.
Digital forensics is the systematic collection, preservation, analysis, and presentation of digital evidence following security incidents or for legal proceedings. Forensic investigation determines what happened, when, how, and who was responsible. Forensics requires proper evidence handling to maintain chain of custody and legal admissibility. Forensic capabilities range from basic log analysis to advanced memory forensics and malware reverse engineering.
Why It Matters
The DSC Perspective:
Forensics tells you what actually happened. Proper evidence preservation is critical if legal action may follow. Know when to engage forensic specialists—complex incidents may exceed internal capability.
