Skip to content

Cyber Forensics

Definition

The branch of forensic science concerned with collecting, preserving, and analysing digital evidence from networked environments for use in legal proceedings. Covers network traffic, cloud data, server logs, web and email communications, and cross-device event reconstruction.

Scope
Digital evidence from networked environments
Covers
Network traffic, cloud data, server logs, email, cross-device reconstruction
Distinct from
Digital forensics, which also covers standalone device analysis
Output
Evidence prepared for legal proceedings

Common questions

How does cyber forensics differ from the broader field of digital forensics?+

Digital forensics is the umbrella discipline covering any digital device, including a single standalone computer or phone with no network involvement, while cyber forensics specifically focuses on evidence generated by networked activity, such as intrusion traces, cloud service logs, and communications between systems.

Why is cross-device event reconstruction a distinct challenge in cyber forensics?+

Evidence of a single incident is often scattered across multiple systems with different clocks, log formats, and retention periods, so analysts must correlate timestamps and events across devices and services to build one coherent timeline rather than relying on any single source.

What makes cloud data particularly challenging to collect in a cyber forensics investigation?+

Cloud infrastructure is typically controlled by a third-party provider rather than the investigating organisation, so obtaining data often requires legal process served on the provider, and the provider's own retention policies and jurisdiction can limit what evidence is still available by the time it is requested.

Related terms

Chain of Custody
The documented chronological record of who collected, handled, transferred, and examined a piece of evidence. For digital evidence, chain of custody includes...
Indicator of Compromise (IoC)
An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
Cybercrime
Offences where a computer network is the tool or the target. Tool-based cybercrime includes fraud, harassment, and intellectual property theft conducted online....
Digital Forensics
The discipline concerned with the recovery, preservation, and analysis of evidence stored on physical digital devices. Primary evidence sources are disk images,...
Mutual Legal Assistance Treaty (MLAT)
A bilateral or multilateral treaty under which signatory states agree to assist each other in gathering evidence for criminal investigations. MLATs define...
Network Flow Record (NetFlow)
A summarised record of a network conversation: source IP, destination IP, ports, protocol, byte count, and duration. Flow records do not contain...
Network Forensics
A sub-discipline of cyber forensics focused on capturing and analysing network traffic, packet captures, and flow records to reconstruct communications and identify...
Order of Volatility
The sequence in which digital evidence should be collected, ranked from most to least transient. Defined in RFC 3227. CPU registers and...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.