Short answer
Computer forensics (also called digital forensics) is the process of collecting, preserving, and analysing digital evidence from computers, phones, and networks in a way that is legally admissible in court. It is used by police, cybersecurity professionals, and lawyers to investigate cybercrime, fraud, and other offences.
At a glance
- Key stage
- Key Stage 3
- Subject
- Computing
- Type
- Guide
- For
- Students
- Read time
- 5 min
- Last updated
- 8 October 2026
Where this fits
- Key Stage 3Years 7–9This article
- GCSEYears 10–11
Method at a glance
- Seizure
- Imaging
- Hashing
- Analysis
- Reporting
What kinds of cases use computer forensics?
Digital evidence appears in a wide range of investigations:
| Case type | What investigators look for |
|---|---|
| Cybercrime | Malware samples, attacker logs, command-and-control server communications |
| Fraud | Altered documents, deleted emails, financial transaction records |
| Theft | Communication records placing a suspect at a scene, stolen data transfers |
| Child protection | Illegal images, communication with victims, account details |
| Terrorism | Encrypted communications, recruitment material, planning documents |
| Employment disputes | Deleted files, unauthorised access to company systems, email evidence |
What happens when investigators seize a device?
A forensic investigation follows strict steps to ensure evidence is not altered or contaminated:
- Seizure — the device is secured and photographed in situ. If it is on, investigators decide whether to leave it running (to preserve volatile memory — RAM contains active passwords and encryption keys) or to power it off (to prevent remote wiping).
- Imaging — a bit-for-bit forensic copy (disk image) of the storage is created using a write blocker device that prevents any data being written to the original. All analysis is done on the copy, preserving the original as evidence.
- Hashing — a cryptographic hash (e.g. SHA-256) of the original drive and the copy is computed and recorded. If the hashes match, the copy is provably identical to the original.
- Analysis — investigators examine the copy for relevant files, deleted data, logs, browser history, and metadata.
- Reporting — findings are documented clearly enough for a non-technical judge and jury to understand.
How is deleted data recovered?
When you delete a file and empty the recycle bin, the operating system does not immediately overwrite the data. It simply marks the storage space as available for reuse and removes the file's entry from the directory. The data remains physically on the storage medium until something else is written over it.
Forensic tools can:
- Scan for file signatures — many file types begin with known byte sequences (e.g. JPEG files start with
FF D8 FF). Tools scan raw storage for these patterns, recovering files even without directory entries. - Recover from unallocated space — storage marked as "free" may still contain old file contents in full.
- Extract from swap files and temporary folders — the OS keeps copies of recently used file contents in various locations.
- Analyse file system journals — modern file systems (NTFS, ext4) keep a journal of recent operations; deleted files often appear in journal entries.
What is metadata and why is it important to forensic investigators?
Metadata is data about data — information stored alongside a file that describes its properties:
- Creation date and time — when the file was first created.
- Modification date — when it was last changed.
- Access date — when it was last opened.
- Author — embedded in Office documents, PDFs, and images.
- GPS coordinates — photos taken on smartphones often include the precise location where the shot was taken.
- Device identifier — some cameras embed a unique ID in every photo.
Metadata has solved real cases: a suspect claimed they were elsewhere when a photo was taken; the GPS metadata in the EXIF data of the image placed them at the crime scene.
What is the chain of custody and why does it matter?
The chain of custody is a documented record of everyone who has had access to a piece of evidence from the moment of seizure to its presentation in court. Every transfer, examination, and storage event is logged with time, date, and the person responsible.
If the chain of custody is broken — if evidence is handled by someone not recorded, or if its integrity cannot be verified — a defence barrister can challenge it, potentially making the evidence inadmissible. The cryptographic hash taken at seizure (step 3 above) is the technical proof that the copy matches the original exactly.
What skills and tools do computer forensics professionals use?
| Skill / Tool | Purpose |
|---|---|
| Autopsy / FTK | Open-source and commercial forensic analysis platforms |
| Wireshark | Capture and analyse network traffic |
| Volatility | Analyse RAM dumps for processes, passwords, and encryption keys |
| Write blockers | Hardware devices preventing any writes to seized media |
| Cryptography | Verifying evidence integrity (hashing) and breaking encrypted data |
| Legal knowledge | Understanding admissibility, privacy law, and proper procedure |
Forensic examiners typically hold qualifications in computer science, cybersecurity, or forensic computing, and may be called as expert witnesses in court.
Frequently asked questions
Can investigators always recover deleted files?
Not always. If the storage space has been overwritten — because the device was used heavily after deletion, or if the user ran a secure-erase tool (which overwrites data with random bytes) — recovery becomes difficult or impossible. SSDs are harder to recover data from than HDDs because they use a process called TRIM that actively clears deleted data blocks for performance reasons.
Is it legal for police to examine my computer without permission?
In the UK, police require a search warrant to seize and examine a device, issued by a magistrate when there is reasonable cause to believe it contains evidence of a crime. Examining someone's device without authorisation is itself a breach of the Computer Misuse Act 1990. Employers may have different rights over company-owned devices, usually specified in an employment contract.
Can private individuals use forensic tools?
The tools themselves are freely available — Autopsy, for instance, is open source. However, using forensic techniques on someone else's device without permission is likely illegal under the Computer Misuse Act. Legitimate uses for individuals include recovering accidentally deleted personal files from their own devices, or investigating their own systems after a suspected intrusion.
How does digital forensics connect to cybersecurity?
Digital forensics and incident response (DFIR) is a combined discipline. When an organisation is hacked, forensic techniques identify what was accessed, how the attacker got in, what data was exfiltrated, and what persistent backdoors were left. This informs both the legal response (is criminal prosecution possible?) and the technical response (how do we fix the vulnerability and prevent recurrence?).
Interested in cybersecurity and digital investigations as a career? Professor Turing at aitutors.me can explore the Computer Misuse Act, cybersecurity topics, and more with you.
Key terms
- Seizure
- Imaging
- bit-for-bit forensic copy
- write blocker
- Hashing
- Analysis
- Reporting
- Scan for file signatures