Digital Forensics is the process of collecting, analyzing & preserving digital evidence in a manner that maintains its integrity for use in legal proceedings.
It involves finding, obtaining, processing & documenting electronically stored data, which is crucial for law enforcement investigations as electronic evidence is often involved in criminal activities.
What is the Goal of Digital Forensics
It is to uncover & intercept electronic data while ensuring that the evidence remains in its original form.
What is the Process used
Autopsy = Forensic analyzer
The sleuth kit is a library & a collection of command line tools used to investigate disk images. Autopsy is the GUI program for TSK.
Results of the forensic search carried over the images are displayed. These results help the investigator to locate relevant sections of data in their investigations.
This is used by law enforcement, military & cooperate examiners to investigate the actions taken place on the evidence computer, however it can be used to recover deleted data from digital devices too.