### Digital Forensic Concepts A key element of digital forensics is the **acquisition and analysis of digital forensic data**. That data can be in the form of *drives*, *files*, *copies of live memory*, and any of the other multitude of *digital artefacts* that we create in the normal process of using computers and networks. Gathering that forensic data is just the start of a process that *involves careful documentation* and detailed analysis. Throughout the process, the **creation of documentation** is necessary in order to be successful. You will document *timelines* and *sequences of events*, looking for clues as to what occurred and why, and use *time stamps, file metadata, event logs*, and a multitude of clues to piece together a complete picture. The human side of digital forensics can also be important; **interviews with individuals** involved in the activity can provide important clues. That means you can't merely be a technical forensics expert in some cases—instead, you have to leverage your knowledge of *both technology and human behaviours* to complete your forensic effort. - [[Legal Holds and e-Discovery]] ### [[Conducting Digital Forensics]] ### [[Reporting]] ### Digital Forensics and Intelligence Although digital forensics work in most organisations is primarily used for legal cases, internal investigations, and incident response (IR), digital forensics **also plays a role in both strategic intelligence and counterintelligence efforts**. The ability to analyse adversary actions and technology, including components and behaviours of advanced persistent threat tools and processes, has become a key tool in the arsenal for national defence and intelligence groups. At the same time, forensic capabilities *can be used for intelligence operations when systems and devices are recovered or acquired*, allowing forensic practitioners to recover data and provide it for analysis by intelligence organisations. Many of the tools that are used by traditional forensic practitioners are also part of the toolset used by intelligence and counterintelligence organisations. In addition to those capabilities, they require advanced methods of breaking encryption, analysing software and hardware, and recovering data from systems and devices that are designed to resist or entirely prevent tampering that would be part of a typical forensic process.