Cyber forensics, or digital forensics, is the branch of forensic science that deals with the identification, preservation, extraction, analysis and presentation of digital evidence from computers, mobile phones, networks and storage media. It has become essential with the rapid growth of cyber crime.
Investigators create forensic images of digital media to preserve the original data, maintain a strict chain of custody, and use specialised tools to recover deleted files, examine logs, trace network activity and analyse malware while ensuring the integrity of the evidence.
Digital evidence includes files, emails, chat logs, browsing history, images, deleted data, metadata, system and network logs, and data recovered from mobile devices, cloud storage and IoT devices.
The digital forensic process follows four key phases – acquisition (bit-by-bit imaging), preservation (hashing and chain of custody), analysis (recovery and examination) and reporting – to ensure that evidence is admissible in court.

