Computer Forensics is the practice of determining the past actions that have taken place on a particular computer system using computer forensic techniques. It is the science of recovering deleted evidence from a computer system.
Computer Forensic provides the ability to search and analyze various pieces of potential evidence of electronic nature. Evidence can involve Hard Drive, Server, Portable Storage (e.g. USB pen drive, Memory card), Portable music player (e.g. ipod) and medium of storage devices (e.g. External hard disk).
All form of evidences are verified and cloned or duplicated prior to investigation to ensure the integrity of the evidence. Computer Forensic evidence plays a crucial role in the threat management life cycle, from incidence response to high stake corporate litigation.