In computer terms, forensic is used to describe the science (or art) of extracting and gathering data from a computer to determine how an intrusion occurred, when it occurred and who the intruder was. Organizations that employ good security practices and maintain logs of network and file access are able to accomplish this much easier. But, with the right knowledge and the right tools forensic evidence can be extracted even from burned, water-logged or physically damaged computer systems.

