TechKnowSurge
ISC2 CISSP 1.5 NIST NICE K0800 NIST NICE K1055 NIST 800-53 AU-11 NIST NICE K0696 NIST NICE K0802 CompTIA CySA+ 3.2 CompTIA SecurityX 4.1
VideoSecurityFree

Digital Forensics

Digital forensics is the practice of collecting, preserving, and analyzing electronic evidence to support criminal investigations, internal inquiries, or legal proceedings. This content covers the core forensics process and key legal concepts such as litigation holds and e-discovery.

Complete this video to capture a CTF flag worth 1 point.

About this video

Digital forensics is the discipline of identifying, acquiring, preserving, and analyzing electronic data to produce findings that can withstand legal and investigative scrutiny. It applies to a wide range of situations, from criminal intrusions into corporate networks to internal workplace investigations, and it follows the same rigorous evidence-handling principles regardless of the context. The goal is to locate and document artifacts that confirm or refute a specific set of facts, ensuring that every piece of evidence collected accurately reflects the state of the systems involved. When legal action is anticipated or underway, organizations face additional obligations around how data is managed. A litigation hold requires that relevant electronic records, spanning email, instant messaging, files, databases, archives, and backups, be frozen in their current state to prevent accidental or intentional alteration. E-discovery then compels the organization to retrieve and submit that data to the court system, where it will serve as evidence for or against the claims being made. Mishandling data at any stage can compromise its admissibility and expose the organization to further legal risk. The digital forensics process follows a defined sequence: identify the data that is relevant, acquire it through approved methods, preserve its integrity, analyze it for meaningful findings, and produce a formal report of conclusions. Each step must be executed carefully and documented thoroughly, particularly when the results will be reviewed by law enforcement, legal counsel, or a court. A solid understanding of this process is foundational for anyone working in IT security or systems administration who may be called upon to support an investigation.

What you'll learn

What's covered

Digital Forensics

Aligned to

ISC2 CISSP
1.5 Understand requirements for investigation types
NIST NICE
K0800 Knowledge of evidence admissibility laws and regulations
K1055 Knowledge of digital forensics principles and practices
K0696 Knowledge of digital forensic data principles and practices
K0802 Knowledge of chain of custody policies and procedures
NIST 800-53
AU-11 Audit Record Retention
CompTIA CySA+
3.2 Given a scenario, perform incident response activities
CompTIA SecurityX
4.1 Given a scenario, analyze the output of a network forensics investigation

Key terms

Digital Forensics
Digital Forensics is the science of collecting, preserving, analyzing, and presenting electronic evidence in a legally sound manner to support incident investigations or criminal proceedings.
Evidence
Facts or information collected during an investigation that indicate whether a belief or claim is valid or true.
Legal Hold
A directive that freezes or preserves relevant data and records to prevent alteration or deletion during an anticipated or active legal proceeding.
E-Discovery
The process of identifying, collecting, and reviewing electronically stored information—such as emails, documents, and databases—as part of a legal action or dispute.
Chain of Custody
CoC
Chain of Custody is the chronological documentation of who has collected, handled, and transferred digital evidence, establishing its integrity and admissibility in legal proceedings.
Data Integrity
The assurance that data has not been altered or corrupted during storage or transmission.

Topics

Digital Forensics E Discovery Legal Hold Evidence Preservation Forensic Analysis Cybersecurity

Transcript

There are times that we have to dig in to figure out what's going on on our systems. We're going to have to do a lot of investigation. Sometimes we're going to have to do a digital forensics. Digital forensics takes this to the next level. It's the same type of investigations we would do for other incidents, but maybe this is around some sort of criminal behavior and we need to collect the evidence correctly.

What Digital Forensics Is

Digital forensics is the practice of analyzing and preserving electronic data. Most of the time when we hear this term digital forensics, it's really related to criminal activity, that we're collecting data and analyzing data in reference to some sort of criminal activity, like somebody hacking your network.

During this process, we're going to collect evidence. Evidence is facts or information indicating a belief is valid or true. So essentially what we're going to be doing is trying to find all these artifacts, all these items out there that are showing that somebody did in fact break into our network and carry out this criminal behavior. So we're going to be collecting evidence for that.

We could be collecting evidence for maybe some sort of root cause analysis. Maybe we're doing it for some sort of internal investigation. Maybe it's for some litigation, some sort of legal action. So much of what we're going to cover and look into is really going to be as if we're complying to some sort of investigation, that maybe we're working with some sort of local law authority to collect evidence for this investigation.

A Litigation Scenario

Let's come up with a little scenario here. Let's say there was an employee who was fired, and now they're coming back and they're suing the company for discrimination, that they felt like they were discriminated against, and so they're taking it to the court system.

One thing that their lawyers might do is, first of all, ask for a legal hold, or a litigation hold. The thing is that we have a lot of dynamic systems. There's email systems, there's instant messaging systems, there's files, there's databases, there's archives. We've got these different systems out there. Some of them are more dynamic than others, but they're changing over time. So they don't want certain information to be deleted or removed or moved around. So what they need to do is preserve that evidence. So one thing that their lawyers might do is ask for a legal hold on certain information with that company.

They're also probably going to ask for some sort of e-discovery. The E just means electronic, so let's ignore that and just talk about what a discovery is. A discovery is when you have to pull documents and submit them to the courts and the legal system as evidence, and it will prove one way or another — either proven that the company did things wrong or right, and prove whether this discrimination happened or not. So what we're going to do is pull evidence of that, and we're going to have to do it whether it's paper or electronic.

Well, in this case right here we're talking about e-discovery. So, since we're mainly talking about technology, we might have to go into email, or like I say, instant messaging, or files, or database, or archives, or backups. We're going to have to go into these sources and pull certain data.

The Forensics Process

Since this data is going to be submitted to the court systems, we need to make sure that we go through the digital forensics process accurately, so that way we don't run into any legal issues during this process. So we're going to somehow identify what data it is that we need to pull and be able to store. We're going to acquire that, go through the process of acquiring that. We need to preserve that data. We would then analyze that data, and then we turn it into some sort of report.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →