Digital Forensics: Collection and analysis of cyber attack evidence. Who does it: 1) Penetration testing firm (preliminary), 2) Certified digital forensics expert, 3) Police (Cyber Crimes Branch) — for criminal cases, 4) Private consultants (independent third-party investigation). Process: 1) Scene preservation (don't touch anything after the incident), 2) Device acquisition (disk imaging: read-only copy, hash verification), 3) Analysis (file recovery, timeline reconstruction, malware analysis), 4) Chain of custody (documentation: who held it, when), 5) Report (findings, methodology, conclusion). Report contents: 1) Executive summary (what was found, conclusion), 2) Methodology (how the analysis was performed), 3) Detailed findings (file timeline, malware signatures, user activity logs), 4) Appendix (technical details, hash values, screenshots). Evidence value: Depends on scientific and procedural validity (chain of custody must be intact). Legal acceptance: In criminal cases initiated with the police, the prosecution may request a special report; in compensation lawsuits, insurance/peer reports are accepted. Cost: $2k-10k depending on complexity (number of devices, malware complexity).