Computer forensics is the process of identifying, preserving, analyzing and presenting digital evidence in a way that is legally acceptable. It aims to find criminal evidence and present it legally to punish criminals. The main steps are identifying evidence through acquisition and collection, preserving it, analyzing and extracting information from it, documenting the process, and presenting findings. It requires forensic tools like disk imaging software, hashing tools, and password cracking software. It is used for criminal prosecution, civil litigation, detecting financial fraud, and investigating corporate policy violations.