This document discusses computer forensics and evidence collection in the cloud computing environment. It defines computer forensics and its aims to identify, analyze and present digital evidence legally. Evidence can be found in various sources like logs, storage media, browsers and memory. Logs provide details of activities, attacks and errors. Evidence is also collected from cloud storage and browsing history. Physical memory analysis allows retrieval of volatile data from memory dumps.