Disk Forensics
Noun · Security & Infosec
Definitions
The forensic examination of storage media and file systems to recover artifacts, timelines, deleted files, and evidence of system activity. Disk forensics remains important even in cloud-heavy environments because persistent media can preserve crucial traces an attacker missed.
In plain English: Investigating storage devices to recover evidence and activity history.
Example: "Disk forensics recovered the dropped tools even though the attacker cleared some visible logs."
Related Terms
- Incident Forensics
- Automated Response
- Cloud Forensics
- Compromise Assessment
- Credential Store
- Email Header Analysis
- Emergency Patching
- Endpoint Isolation
- File Carving
- Forensic Artifact
- Forensic Image
- Forensic Investigation
- Forensic Workstation
- Image Forensics
- Incident Investigation
- Incident Timeline
- Intrusion Analysis
- IRP
- Live Forensics
- Live Response
- Network Traffic Analysis
- Packet Analysis
- Password Salt
- Payload Analysis
- Protocol Analysis
- Response Automation