Cyber Forensics: Meaning, Types and Process
Acquire, preserve, analyse, report, using methods another examiner could repeat.
Cyber forensics, also called digital forensics, is the use of scientific methods to acquire, preserve, analyse and report on digital evidence so that the findings hold up in court. RBI's 2026 cyber Directions define it in those terms and add that the methods must be demonstrably reliable, accurate and repeatable. Repeatable is the key word: another examiner, using the same copy and method, should reach the same result.
For a bank, forensics answers the questions that follow an incident. How did the attacker get in? Which systems and customer accounts were touched? When did it start? Was data taken? The answers drive containment, customer communication, the fraud report and any prosecution.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
Branches of Cyber Forensics
Computer or disk forensics
What it examines
Hard disks and storage: files, deleted data, timelines
Bank example
The PC of a teller suspected of altering dormant accounts
Network forensics
What it examines
Traffic captures, firewall and proxy logs
Bank example
Tracing data sent out of the network after a breach
Memory forensics
What it examines
Contents of RAM, captured from a running system
Bank example
Malware that runs only in memory and leaves little on disk
Mobile forensics
What it examines
Phones: SMS, call logs, installed apps
Bank example
A customer's phone with a remote-access app installed by a fake caller
Malware forensics
What it examines
How a malicious program behaves and what it changes
Bank example
A trojan found on a branch PC
Log and database forensics
What it examines
Application, database and audit logs
Bank example
Who changed a payment file before it went to the clearing system
| Branch | What it examines | Bank example |
|---|---|---|
| Computer or disk forensics | Hard disks and storage: files, deleted data, timelines | The PC of a teller suspected of altering dormant accounts |
| Network forensics | Traffic captures, firewall and proxy logs | Tracing data sent out of the network after a breach |
| Memory forensics | Contents of RAM, captured from a running system | Malware that runs only in memory and leaves little on disk |
| Mobile forensics | Phones: SMS, call logs, installed apps | A customer's phone with a remote-access app installed by a fake caller |
| Malware forensics | How a malicious program behaves and what it changes | A trojan found on a branch PC |
| Log and database forensics | Application, database and audit logs | Who changed a payment file before it went to the clearing system |
The Forensic Process
- 1
Identification
Decide which devices, logs and accounts are relevant, and stop them being overwritten.
- 2
Acquisition
Take a verified forensic image of storage, or capture volatile data such as memory before power is lost.
- 3
Preservation
Hash the image, seal the original and record every handover in the chain of custody.
- 4
Analysis
Work on the copy: rebuild the timeline, recover deleted items, identify indicators of compromise and the root cause.
- 5
Reporting
Write findings so a non-technical reader, a judge or the bank's board, can follow them, with methods stated so they can be repeated.
What RBI Expects of a Bank
From RBI's Cybersecurity, Technology Risk Directions, 2026 for commercial banks.
- check_circleHave network forensics, forensic investigation and DDoS mitigation support on standby.
- check_circleKeep audit trails detailed enough to serve as forensic evidence and to settle disputes, including non-repudiation.
- check_circleAnalyse incidents, through forensics where necessary, for severity, impact and root cause.
- check_circleEquip the Cyber Security Operations Centre with malware analysis and imaging tools for forensics, and the ability to find the root cause of attacks and collect indicators of compromise.
- check_circleAlign the Security Operations Centre, incident response and digital forensics to cut downtime.
Quick practice on banking operations. No signup.
Forensics in Court
- Examiner of Electronic Evidence
- A government department, body or agency notified by the Central Government under section 79A of the IT Act to give expert opinion on electronic evidence. Under section 39(2) of the BSA, its opinion is a relevant fact and the examiner is treated as an expert.
- National Cyber Forensic Laboratory (NCFL)
- Set up in New Delhi under I4C to support law enforcement with memory, mobile, network log, malware and cryptocurrency forensics, and data extraction from damaged disks.
- Forensic expert at the scene
- Under BNSS section 176(3), for offences punishable with seven years or more, a forensic expert visits the crime scene and the process is videographed, from the date each State notifies.
How the IIBF Exam Tests This
Expect definition questions (what digital forensics is and why it must be repeatable), sequence questions (acquisition comes before analysis; analysis is done on the copy), and matching questions on branches. A common trap offers "analyse the original device directly to save time" as a correct step. It is the classic forensic mistake. Another trap confuses forensics with prevention: forensics is a post-incident, investigative activity, though its findings feed back into prevention controls.
FAQs
What is cyber forensics?expand_more
The scientific process of acquiring, preserving, analysing and reporting on digital evidence using methods that are reliable, accurate and repeatable, so the findings can be relied on in court.
What are the types of digital forensics?expand_more
The main branches are computer or disk, network, memory, mobile, malware, and log or database forensics. Each covers a different source of evidence.
Who is an Examiner of Electronic Evidence?expand_more
A government body notified under section 79A of the IT Act to give expert opinion on electronic evidence. Courts treat its opinion as a relevant fact under section 39(2) of the Bharatiya Sakshya Adhiniyam.
Why is forensic analysis done on a copy?expand_more
Working on the original can change it. Analysts use a verified image with a matching hash value, so the original stays intact and the results can be repeated.
Next steps
Take a full IIBF Cyber Crimes mock test120 questions, 2 hours, scored instantly.
