in most cases forensics is the process after there has been an compromise or searching for specific data who can lead to evidence of a case.
The president got security, so he will not get shot by some random guy, when he gets shot, a forensics team will find out how this could happen and who did it and then passing it back to the security world so they can take measurements so it will not happen again.
Tools like wireshark can be used to do research on for example .pcap file who are files who contain very detailed network logs (the packets), and you can extract everything from them, when you capture data with wireshark it will be saved to the same file type for later research.