Network Forensics
Forensic acquisition and analysis of network traffic and related metadata to reconstruct communication behavior, timing and evidence relationships.
Evidence from Communication
Network forensics uses packet captures, flow records, DNS/proxy logs and related telemetry to reconstruct who communicated, when, over which protocol and with what observable content or metadata.
A PCAP preserves packets, but interpretation still requires protocol context and a defensible timeline.
Limits
Encrypted traffic can hide application payload while still exposing endpoints, timing, sizes and handshake metadata. NAT, proxies and shared infrastructure can also weaken direct attribution.
Network evidence should therefore be correlated with host, identity and application artifacts.
Forensic Practice
Capture provenance, clock quality and evidence handling matter as much as parser output.
See also Chain of Custody and Memory Forensics.