ABSTRACT

Digital forensics is looked at in this chapter. An initial overview is given before drilling down into the actual techniques and analysis involved. The various devices that digital forensics can be applied to are reviewed before looking at how information retrieval can take place and the tools involved. Linux distributions are detailed, which contain appropriate packages, including Kali, Parrot, BlackArch and Backbox. Log files, temporal analysis, reconstruction and restoration of data are all looked at here.