The methods employed for the collection of computer evidence can be one of the most highly scrutinized areas of the computer forensics process. It is essential that investigators use tested and proven methodologies and tools during this task. Part IV, “Artifact Collection,” provides detailed procedures for artifact collection as well as a discussion about an array of tools available for digital evidence collection. In Part IV, investigators are shown the importance of collecting volatile data in addition to static data on disk. Single systems and large-scale evidence collection methodologies are discussed.