Computer forensics involves the preservation, identification, extraction, documentation, and analysis of computer data. Computer forensic examiners follow clear, well-defined methodologies and procedures that can be adapted for specific situations.As digital devices and technology continue to evolve, forensic tools need to advance in a lockstep fashion. Forensic toolkits are intended to facilitate the work of examiners, allowing them to perform the above-mentioned steps in a timely and structured manner, and improve the quality of the results.
This paper discusses available forensic tools, highlighting the facilities offered and associated constraints on use. Most PDAs follow a similar basic design and offer comparable capabilities. While similar in principle, the various families of PDAs on the marketplace differ in such areas as interaction style, Operating System (OS), and hardware components.