End-to-end digital forensics and incident response (DFIR) workflow. Covers evidence acquisition with chain of custody, disk and memory forensics, network forensics, cloud and mobile evidence, and timeline reconstruction. Triggers for: incident investigation, evidence collection, memory forensics, disk imaging, DFIR engagements, or legal/regulatory evidence requirements.