Topic 1 of 5
What is digital forensics?
Digital forensics is the secured capture, examination and documentation of digital traces on computers, mobile devices and storage media. Its aim is a verifiable answer to a clearly defined question. Work is carried out on verified copies, never on the original. What cannot be proven technically is stated as a limitation rather than replaced by assumptions.
A forensic examination starts with the question, not the tool. Only once it is clear what needs to be established – an access time, a copied file, a suspicious sign-in – is it decided which data sources matter and in which order they are secured. Volatile data such as memory contents and active connections are lost on shutdown and are therefore captured first wherever possible.
The analysis itself is performed on a secured working copy. The original remains stored unchanged so that an independent review stays possible. Findings are documented so that a qualified third party can retrace every step from the source material to the conclusion.
The levels must stay separate: a technical finding describes what a system recorded. The assessment explains what that finding may mean – and under which conditions. Whether a result is used in proceedings is decided solely by courts or investigating authorities.
