Digital Forensics System Model Digital evidence may be found in many layers and many statuses as shown

Axis Y: Defines the phases that all digital evidences should go through to deliver consistent and admissible report
• Acquisition.
• Analysis.
• Reconstruction. Acquisition: involves the evidence search, evidence recognition, evidence collection and documentation Analysis: determines evidence’s significance and probative value to the case by looking at its visibility and explaining its origin. Reconstruction: involves organizing the results from the analysis done and using them to develop a theory for the incident drawing conclusions about what happened. Axis Z: defines the Place (Where the digital evidence exists?) Evidence can be found in the System, Application, or Network, but regardless of the location of evidences they all should go through the steps of acquisition, analysis, and reconstruction to reach the answer of the 5Ws (Who, What, When, Where, Why) but to decide start-point and path of investigation which are influenced by the factors of the third axis.
Axis X: defines the challenges exits with our digital evidence:
• Volatility
• Visualization
• Virtuality
Volatility: "Is the digital evidences persistent or not?" The following figure shows the relation between the ‘RAM’ with reference to ‘Time in Nano Second’. Which means the content of memory could be changed within a Nano second. High level of volatility means more chances of possible failure to produce relevant, enough and admissible evidence which leads failed investigations.
Visualization: "How is the data physically viewed? i.e. (encrypted or plaintext state)" The physical appearance of evidence is a main factor that influences the investigation. Encryption for instance is creating challenges for forensic examiners, potentially preventing them from recovering any digital evidence, the influence of encryption challenge over the three possible evidence locations as follows: • System forensics: The integration of strong encryption into operating systems "File-system level encryption" prevents investigators to access to any data on the computer. • Application forensics, logs will always play a key role in any evidence-based investigation, as they help to preserve evidence and shorten investigation times encrypted application logs will prevent investigators to extract and analyze them. • Network forensic, Attack could be tunneled through non-standard protocols and encrypted traffic cannot be analyzed or traced by investigators
Virtuality: "Is it virtualized environment ?" Today virtual environment can be created by software and hardware, in virtual forensics, the lack of physical access to recourses constitutes a disruptive challenge for investigators. "Cloud Computing". Is an obvious instance to show challenges investigators can encounter in virtual environment. Cloud Computing is a model for enabling convenient, on-demand network access to a shared pool of computing resources (e.g., networks, servers, storage, applications and services).The virtual instances for Cloud environment, where i.e. data is stored or processes are handled virtually provide a complex issue to conduct valid forensic investigation, and due to the decentralized nature of data processing in the Cloud, traditional approaches to evidence collection and recovery can fail the investigation. After identifying the notional foundations and factors influencing digital forensics findings and paths.