A digital forensics primer
What is digital forensics?
Digital forensics is the preservation, examination, and reporting of data from phones, computers, and online accounts, using methods that let another examiner verify the results and a court admit them as evidence.
§ 01 · What a device holds
Four kinds of data
Data is more than just files on a disk. A forensic examination looks deeper to find more.
01
Content
What the user sees: messages, emails, photos, documents, browser history.
02
Metadata
Data about the content: when a file was created or edited, by which account, on which device, and where a photo was taken.
03
System records
Logs the operating system keeps automatically: app usage, USB connections, Wi-Fi networks, sign-ins. Users rarely know they exist.
04
Deleted data
Deleted items sometimes remain in databases, backups, or synced accounts. Whether they can be recovered depends on the device and how much time has passed.
§ 02 · How it differs
Digital forensics, e-discovery, and IT recovery
| Digital forensics | E-discovery | IT data recovery | |
|---|---|---|---|
| Question | What happened on this device, when, and is it authentic? | Which documents are relevant and must be produced? | Can we get the files back? |
| Focus | Metadata, system records, deleted data, timelines | Content at scale: review for relevance and privilege | Usable copies of lost files |
| Original device | Preserved; work done on a verified copy | Collected; usually not analyzed | Often altered in the process |
| Output | Expert report, declarations, testimony | Production sets, privilege logs | Recovered files |
The disciplines overlap. A forensic examiner often works alongside an e-discovery vendor, for example to authenticate key documents from a production.
§ 03 · What it can and cannot show
Realistic expectations
Often can establish
- When a message was sent, read, or deleted
- Whether files were copied to a USB drive or cloud account
- Whether a document or photo was edited after the date it claims
- Whether a screenshot matches the underlying message data
- The device’s approximate location at a given time
- Whether a phone was in active use at a specific moment
Often cannot establish on its own
- Who was physically holding the device — this usually requires other evidence
- Data that has been overwritten, or a device that was reset
- Exact location; precision varies from meters to miles by source
- Encrypted content without access to the device or account
- Anything from a device or account that was never preserved
Which of these apply depends on the devices, accounts, and time involved in a particular matter.
§ 04 · Key terms
Terms you will see in a forensic report
- Forensic image
- An exact copy of a device’s storage, made without altering the original. Analysis is done on the image.
- Hash value
- A fingerprint calculated from data (for example, SHA-256). If one bit changes, the hash changes, which proves the copy is unaltered.
- Chain of custody
- The documented record of who had the evidence, when, and what was done with it.
- Extraction
- How data is acquired from a phone. A logical extraction captures less than a full file system extraction; the type affects what can be found.
- Artifact
- A specific record left by the system or an app, such as a database entry showing when an app was opened.
- ESI
- Electronically stored information — the discovery-rule term for digital data of any kind.
- Litigation hold
- The duty, once litigation is reasonably anticipated, to stop deleting relevant data and suspend routine disposal.
- Spoliation
- The destruction or alteration of evidence. A forensic examination can often show whether and when it occurred.
§ 05 · In Washington courts
Rules that shape the work
- ER 702
- Expert testimony must come from a witness qualified by knowledge, skill, experience, training, or education, and must help the trier of fact.
- Frye
- Washington applies the Frye standard: novel scientific methods must be generally accepted in the relevant scientific community.
- ER 901
- Evidence must be authenticated — shown to be what it is claimed to be. Forensic analysis is one way to authenticate, or challenge, digital exhibits.
General information only; not legal advice.