Patent attributes
A digital forensics system includes an ingestion system, an analysis system including analysis workstations, an archive system including storage arrays, and a server system including an evidence storage server and a virtual desktop server. The ingestion system includes ingestion workstations operable to receive extracted data from devices under analysis. The evidence storage server includes resources operable to generate evidence packages based on extracted data from the devices under analysis. The virtual desktop server includes resources operable to generate virtual desktop sessions that interface with the analysis workstations and interface with the evidence storage server to access the extracted data in the evidence packages, store work products in the evidence packages based on a forensic analysis of the extracted data in the evidence packages, and store associated work products with a second copy of extracted data to the archive system.