Data acquisition

Forensics investigation involves the acquisition, preservation, analysis, and presentation of computer evidence. This type of evidence is fragile in nature and can easily, (or even inadvertently), be altered, destroyed, or rendered inadmissible as evidence. Computer evidence can be obtained, preserved, and analysed to be accepted as reliable and valid in a court of law with dedicated packages such as AccessData FTK and EnCase. Most of the commonly used forensics file formats were developed with a specific forensics package and are program-specific, but not all.