Operating System Forensics

The investigation of an OS (e.g., Windows, Linux) to recover evidence from system files, logs, or registry entries, revealing user actions or system compromises.