THREAT-WATCH logo

THREAT‑WATCH

Glossary

Digital Forensics

The scientific process of collecting, preserving, and analyzing digital evidence to determine what happened during a security incident.

Digital forensics reconstructs an attacker's actions, entry point, and scope of access by examining logs, memory, disk images, and network traffic, following strict evidence-handling procedures (chain of custody) so findings hold up for legal, regulatory, or insurance purposes. It's a core part of proper incident response, not just an academic exercise after the fact.