Introduction to digital forensics
Digital forensics (also known as cyber forensics or just forensics) is the process used to collect, identify, gather, secure, and store data from digital systems that can be used as evidence.
In our case, we will focus on forensics to detect the use, abuse, intrusion, damage, or modification of computer systems, servers, networks, infrastructures, or data. However, forensics is also used to recover deleted or modified data, so let's take a few minutes to review how forensics can be used for that.
Forensics to recover deleted or missing data
There is one part of forensics that is used to collect, identify, and recover deleted data from digital media.
Usually, data is recovered from non-volatile media storage such as hard drives and USB drives, but it is also possible to gather data from volatile memory such as Random Access Memory (RAM).
Volatile versus non-volatile memory
Volatile memory such as RAM is a type of memory that...