Glossary term
Computer Forensics
Computer forensics is the systematic examination of laptops, desktops, and servers to recover, preserve, and analyse digital evidence to a court-admissible standard.
Computer forensics is the oldest branch of digital forensics, dating back to law enforcement examinations of personal computers in the 1980s and 1990s. The discipline now covers Windows, macOS, and Linux systems, including encrypted volumes (BitLocker, FileVault, VeraCrypt, LUKS) and modern fast-storage architectures.
A typical computer forensic examination starts with a hardware write-blocker imaging of the source media, hash verification, and decryption of any encrypted volumes on the working copy. Analysis covers user activity (event logs, recently used artifacts), file access (MFT, USN journal, file system metadata), program execution (Prefetch, Amcache, Background Activity Moderator), browser history, cloud sync state, USB connection records, and email content.
Common matters include departing-employee investigations, IP theft, internal fraud, and litigation production support. The deliverable is a written examiner report tying findings to specific exhibits.
