Defensive Security (Blue Team) / Response and recovery
Lesson 27 of 32
Digital forensics
Forensics collects and studies evidence carefully so it can be trusted. Analysts copy disks and memory, hash the copies, and work only on the copies.
Key points
- Work on copies, never the original
- Hash evidence to prove it's unchanged
- Record a chain of custody
Quiz · +10 XP
Why do forensic analysts hash evidence copies?
Log in to save progress and earn XP.