Lecture Note: Disk, Memory, and Network Forensics
Digital forensics involves the collection, preservation, analysis, and presentation of electronic evidence. Three critical areas in this field are disk forensics, memory forensics, and network forensics. Each focuses on a different data source, but together they provide a complete picture of an incident.
Focus: Storage media such as hard drives, SSDs, and USBs.
Objective: Recover and analyze data to determine user actions and system events.
Key Tasks:
Use Cases:
Focus: Volatile memory (RAM).
Objective: Capture and analyze live system data that is lost when the system is powered off.
Key Tasks:
Use Cases:
Focus: Data transmitted across a network.
Objective: Capture, record, and analyze network traffic to detect malicious activities and reconstruct communication patterns.
Key Tasks:
Use Cases:
Disk, memory, and network forensics complement one another:
Together, they provide a holistic understanding of cyber incidents and support accurate reconstruction of attack scenarios.
Copyright © 2026 | WordPress Theme by MH Themes
Be the first to comment