A digital forensics primer

What is digital forensics?

Updated

Digital forensics is the preservation, examination, and reporting of data from phones, computers, and online accounts, using methods that let another examiner verify the results and a court admit them as evidence.

§ 01 · What a device holds

Four kinds of data

Data is more than just files on a disk. A forensic examination looks deeper to find more.

01

Content

What the user sees: messages, emails, photos, documents, browser history.

02

Metadata

Data about the content: when a file was created or edited, by which account, on which device, and where a photo was taken.

03

System records

Logs the operating system keeps automatically: app usage, USB connections, Wi-Fi networks, sign-ins. Users rarely know they exist.

04

Deleted data

Deleted items sometimes remain in databases, backups, or synced accounts. Whether they can be recovered depends on the device and how much time has passed.

§ 02 · How it differs

Digital forensics, e-discovery, and IT recovery

Digital forensics E-discovery IT data recovery
QuestionWhat happened on this device, when, and is it authentic?Which documents are relevant and must be produced?Can we get the files back?
FocusMetadata, system records, deleted data, timelinesContent at scale: review for relevance and privilegeUsable copies of lost files
Original devicePreserved; work done on a verified copyCollected; usually not analyzedOften altered in the process
OutputExpert report, declarations, testimonyProduction sets, privilege logsRecovered files

The disciplines overlap. A forensic examiner often works alongside an e-discovery vendor, for example to authenticate key documents from a production.

§ 03 · What it can and cannot show

Realistic expectations

Often can establish

  • When a message was sent, read, or deleted
  • Whether files were copied to a USB drive or cloud account
  • Whether a document or photo was edited after the date it claims
  • Whether a screenshot matches the underlying message data
  • The device’s approximate location at a given time
  • Whether a phone was in active use at a specific moment

Often cannot establish on its own

  • Who was physically holding the device — this usually requires other evidence
  • Data that has been overwritten, or a device that was reset
  • Exact location; precision varies from meters to miles by source
  • Encrypted content without access to the device or account
  • Anything from a device or account that was never preserved

Which of these apply depends on the devices, accounts, and time involved in a particular matter.

§ 04 · Key terms

Terms you will see in a forensic report

Forensic image
An exact copy of a device’s storage, made without altering the original. Analysis is done on the image.
Hash value
A fingerprint calculated from data (for example, SHA-256). If one bit changes, the hash changes, which proves the copy is unaltered.
Chain of custody
The documented record of who had the evidence, when, and what was done with it.
Extraction
How data is acquired from a phone. A logical extraction captures less than a full file system extraction; the type affects what can be found.
Artifact
A specific record left by the system or an app, such as a database entry showing when an app was opened.
ESI
Electronically stored information — the discovery-rule term for digital data of any kind.
Litigation hold
The duty, once litigation is reasonably anticipated, to stop deleting relevant data and suspend routine disposal.
Spoliation
The destruction or alteration of evidence. A forensic examination can often show whether and when it occurred.

§ 05 · In Washington courts

Rules that shape the work

ER 702
Expert testimony must come from a witness qualified by knowledge, skill, experience, training, or education, and must help the trier of fact.
Frye
Washington applies the Frye standard: novel scientific methods must be generally accepted in the relevant scientific community.
ER 901
Evidence must be authenticated — shown to be what it is claimed to be. Forensic analysis is one way to authenticate, or challenge, digital exhibits.

General information only; not legal advice.

About the author

Quartz Digital Forensics

A Seattle digital forensics practice serving attorneys in civil and criminal matters, opening Summer 2027. Principal Examiner Benjamin Hodes has 20 years of experience in the software industry, including over a decade at Microsoft.