KS3 & GCSE Computing · Key Stage 3

What Is Computer Forensics? A KS3 Computing Guide

Learn what computer forensics is for KS3 computing: how investigators recover deleted files, trace digital evidence, and maintain the legal chain of custody.

Duke Harewood — author of AI Tutors for Key Stage 3Updated 5 min read

On this page

Short answer

Computer forensics (also called digital forensics) is the process of collecting, preserving, and analysing digital evidence from computers, phones, and networks in a way that is legally admissible in court. It is used by police, cybersecurity professionals, and lawyers to investigate cybercrime, fraud, and other offences.

At a glance

Key stage
Key Stage 3
Subject
Computing
Type
Guide
For
Students
Read time
5 min
Last updated
8 October 2026

Where this fits

  1. Key Stage 3Years 7–9This article
  2. GCSEYears 10–11
This article is aimed at Key Stage 3 (Years 7–9), the stage before GCSE (Years 10–11).

Method at a glance

  1. Seizure
  2. Imaging
  3. Hashing
  4. Analysis
  5. Reporting
The 5 numbered steps in this article, in order.

What kinds of cases use computer forensics?

Digital evidence appears in a wide range of investigations:

Case type What investigators look for
Cybercrime Malware samples, attacker logs, command-and-control server communications
Fraud Altered documents, deleted emails, financial transaction records
Theft Communication records placing a suspect at a scene, stolen data transfers
Child protection Illegal images, communication with victims, account details
Terrorism Encrypted communications, recruitment material, planning documents
Employment disputes Deleted files, unauthorised access to company systems, email evidence

What happens when investigators seize a device?

A forensic investigation follows strict steps to ensure evidence is not altered or contaminated:

  1. Seizure — the device is secured and photographed in situ. If it is on, investigators decide whether to leave it running (to preserve volatile memory — RAM contains active passwords and encryption keys) or to power it off (to prevent remote wiping).
  2. Imaging — a bit-for-bit forensic copy (disk image) of the storage is created using a write blocker device that prevents any data being written to the original. All analysis is done on the copy, preserving the original as evidence.
  3. Hashing — a cryptographic hash (e.g. SHA-256) of the original drive and the copy is computed and recorded. If the hashes match, the copy is provably identical to the original.
  4. Analysis — investigators examine the copy for relevant files, deleted data, logs, browser history, and metadata.
  5. Reporting — findings are documented clearly enough for a non-technical judge and jury to understand.

How is deleted data recovered?

When you delete a file and empty the recycle bin, the operating system does not immediately overwrite the data. It simply marks the storage space as available for reuse and removes the file's entry from the directory. The data remains physically on the storage medium until something else is written over it.

Forensic tools can:

  • Scan for file signatures — many file types begin with known byte sequences (e.g. JPEG files start with FF D8 FF). Tools scan raw storage for these patterns, recovering files even without directory entries.
  • Recover from unallocated space — storage marked as "free" may still contain old file contents in full.
  • Extract from swap files and temporary folders — the OS keeps copies of recently used file contents in various locations.
  • Analyse file system journals — modern file systems (NTFS, ext4) keep a journal of recent operations; deleted files often appear in journal entries.

What is metadata and why is it important to forensic investigators?

Metadata is data about data — information stored alongside a file that describes its properties:

  • Creation date and time — when the file was first created.
  • Modification date — when it was last changed.
  • Access date — when it was last opened.
  • Author — embedded in Office documents, PDFs, and images.
  • GPS coordinates — photos taken on smartphones often include the precise location where the shot was taken.
  • Device identifier — some cameras embed a unique ID in every photo.

Metadata has solved real cases: a suspect claimed they were elsewhere when a photo was taken; the GPS metadata in the EXIF data of the image placed them at the crime scene.

What is the chain of custody and why does it matter?

The chain of custody is a documented record of everyone who has had access to a piece of evidence from the moment of seizure to its presentation in court. Every transfer, examination, and storage event is logged with time, date, and the person responsible.

If the chain of custody is broken — if evidence is handled by someone not recorded, or if its integrity cannot be verified — a defence barrister can challenge it, potentially making the evidence inadmissible. The cryptographic hash taken at seizure (step 3 above) is the technical proof that the copy matches the original exactly.

What skills and tools do computer forensics professionals use?

Skill / Tool Purpose
Autopsy / FTK Open-source and commercial forensic analysis platforms
Wireshark Capture and analyse network traffic
Volatility Analyse RAM dumps for processes, passwords, and encryption keys
Write blockers Hardware devices preventing any writes to seized media
Cryptography Verifying evidence integrity (hashing) and breaking encrypted data
Legal knowledge Understanding admissibility, privacy law, and proper procedure

Forensic examiners typically hold qualifications in computer science, cybersecurity, or forensic computing, and may be called as expert witnesses in court.

Frequently asked questions

Can investigators always recover deleted files?

Not always. If the storage space has been overwritten — because the device was used heavily after deletion, or if the user ran a secure-erase tool (which overwrites data with random bytes) — recovery becomes difficult or impossible. SSDs are harder to recover data from than HDDs because they use a process called TRIM that actively clears deleted data blocks for performance reasons.

In the UK, police require a search warrant to seize and examine a device, issued by a magistrate when there is reasonable cause to believe it contains evidence of a crime. Examining someone's device without authorisation is itself a breach of the Computer Misuse Act 1990. Employers may have different rights over company-owned devices, usually specified in an employment contract.

Can private individuals use forensic tools?

The tools themselves are freely available — Autopsy, for instance, is open source. However, using forensic techniques on someone else's device without permission is likely illegal under the Computer Misuse Act. Legitimate uses for individuals include recovering accidentally deleted personal files from their own devices, or investigating their own systems after a suspected intrusion.

How does digital forensics connect to cybersecurity?

Digital forensics and incident response (DFIR) is a combined discipline. When an organisation is hacked, forensic techniques identify what was accessed, how the attacker got in, what data was exfiltrated, and what persistent backdoors were left. This informs both the legal response (is criminal prosecution possible?) and the technical response (how do we fix the vulnerability and prevent recurrence?).


Interested in cybersecurity and digital investigations as a career? Professor Turing at aitutors.me can explore the Computer Misuse Act, cybersecurity topics, and more with you.

Key terms

  • Seizure
  • Imaging
  • bit-for-bit forensic copy
  • write blocker
  • Hashing
  • Analysis
  • Reporting
  • Scan for file signatures

Sources