Computer Forensics Service is the whole of the processes that ensure that all kinds of data, such as sound, image, etc., or a combination of these, stored in electromagnetic and electro-optical environments or transmitted by these environments, are examined and the questions requested are answered with evidence. It basically consists of 4 stages:
First Responder: Identifying digital evidence to clarify the incident and ensuring the security of these systems,
Taking Forensic Photocopies: Taking images of systems accepted as digital evidence with write-protection methods,
Analysis: Technical studies on Forensic Copies obtained to find answers to questions asked with methods and software accepted in the literature,
Reporting: Suggestions are made that include the precautions to be taken in order to report the findings and the details of the findings obtained as a result of the investigation in an understandable way and to prevent similar incidents from being investigated.