Computer Forensics
Workflow
- Preserve evidence integrity (hashing, immutable copies, custody logs).
- Acquire and catalog artifacts from disk, memory, logs, and network traces.
- Build timelines and correlate events across sources.
- Identify indicators, attacker actions, and affected assets.
- Produce a defensible report with methods, evidence, and confidence levels.