Network Forensics

What is Network Forensics?

In general, the computer process follows the following steps:

  • Assessment
  • Acquisition & Imaging
  • Culling
  • Analysis
  • Report & Testimony

Digital Investigations on Networks & IT Systems

Network forensics, or IT Forensics, is a form of computer forensics that involves extracting forensic evidence from computer networks, particularly criminal evidence. The extraction can either be from network log files or log information on routers, nodes, and other network devices, or the extraction can be proactive, actively capturing network packets for use as evidence.

Captured network packets can recreate transferred files, analyze security threats, and identify network intruders. Although evidence on a computer or network drive may be destroyed, Network Forensics can identify a culprit by using data stored on network devices to identify unauthorized access to the computer or network device.


