Monday, April 25, 2011

Computer Forensics

Computer forensics is a branch of science that focuses on finding legal evidence in computers and digital storage media.  Computer forensics seeks to uncover, gather, and preserve evidence and information that is magnetically stored.  Computer forensics is often used in criminal investigations or civil court cases.  It can also help recover data that has been lost.  Computer forensics includes the following phases: securing the subject system, taking a copy of the hard drive, identifying and recovering all files, accessing hidden/protected/temporary file, and investigating installed applications or programs.



Computer forensics is commonly used to track employee internet abuse, unauthorized recovery of corporate info.date, industrial espionage, criminal fraud, damage assessment and many other criminal cases.   In many of these criminal cases, information is collected that is not usually obtainable by an average computer user.  Computer forensic investigator and gather deleted files found in the space allocated for existing files, known as slack space. 


To learn more about Computer Forensics go here.

No comments:

Post a Comment