Digital Evidence Collection in Cybersecurity (original) (raw)

Last Updated : 10 Apr, 2026

Digital evidence in cyber forensics refers to electronic data collected and analyzed to investigate cybercrimes and legal cases. It helps forensic experts identify, preserve, and present digital information from computers and other electronic devices.

Electronic Evidence

This includes any digital information that can be used to support an investigation or legal proceeding related to cybercrime.

Process Involved in Digital Evidence Collection

It is a systematic process used to identify, examine, analyze, and document electronic data so that it can be used in cybercrime investigations and legal proceedings.

digital_evidence_2

Collection of Digital Evidence

1. Data Collection

2. Examination

3. Analysis

4. Reporting

Types of Collectible Data

Collectible data refers to the digital information that investigators search for in seized devices during a computer forensic investigation.

1. Persistent Data

This is the information stored on non-volatile storage devices that remains available even when the computer system is turned off.

2. Volatile Data

Volatile data is temporary information stored in memory that is lost when the system is turned off or loses power.

**Types of Evidence

Collecting the shreds of evidence is important in any investigation to support the claims in court. Below are some major types of evidence.

Advantages

Disadvantages