A forensic image captures every sector of a device, including deleted data and unallocated space. A logical copy captures only the files the operating system presents. Both are legitimate; they answer different questions, and choosing the narrower one when the dispute turns on deleted activity is the mistake that cannot be undone later.
| Dimension | Forensic (physical) imageEvery sector of the device, allocated or not. | Logical copyOnly the files the file system presents. |
|---|---|---|
| What is captured | All sectors, including unallocated space, file slack and the file system's own structures. | Active files and folders within a defined scope, as the operating system reports them. |
| Deleted data | Recoverable, until overwritten. Frequently the point of the exercise. | Not captured at all. |
| Activity artifacts | Registry hives, link files, USB history, event logs and shellbags come along with the volume. | Only if those specific files were named in the collection scope. |
| Time and cost | Bounded by device size and read speed. A large array is a multi-day acquisition. | Proportional to the selected data, often minutes to hours. |
| Cloud and SaaS data | Usually impossible — there is no device to image. | The normal method, via the provider's export or API. |
| Proportionality posture | Can be challenged as overbroad where the dispute is narrow. | Easier to defend on burden, harder to defend on completeness. |
| Verification | Hash of the whole device, verifiable against the source at any time. | Hash per file. Provable for what was collected, silent about what was not. |
Choose Forensic (physical) image when
Choose a forensic image when the dispute is about conduct rather than content: suspected data theft, deletion, or anti-forensic activity; any departing-employee or trade-secret matter; anywhere a device itself is the subject of the claim; and whenever there is a realistic prospect that what was removed matters more than what remains. Also choose it when the device is about to leave your control, since the option disappears with the hardware.
Choose Logical copy when
Choose a logical copy when the scope is genuinely and defensibly narrow: a custodian's mailbox in a contract dispute, cloud-only data with no underlying device, a server you cannot take offline, or a court-approved protocol that defines exactly what is collected. It is also the right answer when imaging a personal device would create privacy exposure disproportionate to the question being asked.
Where this goes wrong
The expensive error runs one direction. A logical copy taken in a matter that later turns on deleted activity cannot be upgraded — by the time anyone realises what is missing, the device has usually been reissued, wiped, or simply used enough that the unallocated space is gone. Solid-state drives make this worse, because the drive's own garbage collection can erase deleted content within hours and without anyone touching it. Over-collecting costs money and invites a proportionality fight; under-collecting can end the claim.
Why this is a decision and not a best practice
It is tempting to treat physical imaging as the thorough option and logical collection as the shortcut. That framing produces bad decisions in both directions — it pushes teams toward imaging cloud data that has no device to image, and it makes anyone who chooses a logical collection feel they are cutting corners.
The honest framing is that they capture different things. A physical image answers questions about what happened on a device. A logical collection answers questions about what a custodian had. Most matters need one of those much more than the other, and knowing which is a scoping question that should be asked out loud rather than defaulted into.
The asymmetry that should drive the default
The two errors are not symmetrical, and this is the single most useful thing to understand about the choice.
Over-collect and you have spent money, and you may face a proportionality objection you can lose. Both are recoverable. Under-collect and the evidence is often simply gone: devices get reissued, disks get overwritten by ordinary use, and SSD firmware erases deleted content on its own schedule.
So where the answer is genuinely unclear and the device is available, the imbalance favours imaging — not because more is better, but because one mistake can be corrected and the other cannot.
Preservation and analysis are separate decisions
A useful move when scope is contested: image now, argue about scope later. Acquisition is comparatively cheap and time-sensitive; analysis is expensive and can wait. Taking the image preserves every option, and nothing obliges anyone to analyse all of it — a protocol can limit examination to agreed search terms and date ranges while the underlying image sits sealed.
This also tends to defuse the proportionality objection, because the burden being complained about is usually review burden rather than acquisition burden.
Where the distinction breaks down
Modern matters increasingly involve data that fits neither model cleanly. A phone is acquired through the vendor's protocols, and what is achievable ranges from a near-complete physical extraction to a logical extract of whatever the API exposes, depending entirely on model and OS version. A cloud tenancy has no sectors at all, and integrity comes from documented API collection and hashing the output rather than from imaging.
In those cases the useful question is not which of the two you are doing. It is what the chosen method can and cannot see, and whether that gap intersects the thing in dispute.
From our work
Which one does your matter need?
Our examiners and testifying experts work these questions for a living. Tell us what you're facing.
Reviewed by Law & Forensics. See our editorial standards.
