forensics
termsecuritygovernance & risk
Establishing what happened on a system, in a way that survives being questioned afterwards.
The discipline is defined by that second clause. Anyone can look at a machine; forensics is looking without changing what you are looking at, recording how you know, and being able to show later that the evidence is the same evidence. That is why the first action is usually to capture volatile state and isolate rather than to reboot or clean - and why an organisation that wipes and reimages a compromised host has chosen recovery speed over ever knowing what happened, which is sometimes the right trade and should be a decision rather than a reflex.
Also known as: dfir