Skip to content

Forensic Imaging & Chain of Custody

Every forensic opinion rests on how the evidence was acquired. We image devices and cloud sources to recognized standards, verify integrity with cryptographic hashes, and document custody end to end — so the analysis is argued on its merits rather than on how the data was collected.

Forensic Imaging & Chain of Custody capabilities

  • Write-Blocked Acquisition

    Source media is acquired through a hardware or software write blocker, so the original is never altered by the act of copying it. The acquisition is captured to a forensic container — E01/Ex01, AFF4, or raw — with the tool, version, and operator recorded.

  • Cryptographic Verification

    A hash is computed at acquisition and re-verified afterward, and again whenever a copy is made. A matching hash is what lets an examiner state that the image analyzed today is bit-for-bit identical to the device seized months ago.

  • Chain-of-Custody Documentation

    Every transfer, storage location, and access is logged from seizure onward. The record is built to be produced, not reconstructed later from memory — because a gap in custody is the first thing an opposing expert looks for.

  • Targeted and Logical Acquisition

    Full-disk encryption, cloud platforms, and mobile secure enclaves often make a bit-for-bit physical image impossible. Where that is the case we perform a documented logical or targeted acquisition and say plainly what it does and does not capture, rather than describing it as something it is not.

  • Cloud and SaaS Collection

    Data held by a provider cannot be write-blocked. We collect through supported export and API paths, capture the provider-side metadata that establishes completeness, and document the parameters of the request so the collection can be reproduced.

  • Standards-Aligned Method

    Our procedures follow SWGDE best practices, NIST SP 800-86, and ISO/IEC 27037 for the identification, collection, acquisition, and preservation of digital evidence — the frameworks an opposing expert will measure the work against.

Forensic Imaging & Chain of Custody — matters we are engaged for

  • Preservation before litigation is filed

    Once litigation is reasonably anticipated the duty to preserve attaches, and devices continue to overwrite themselves in the meantime. Imaging early freezes the record while it still exists.

  • Departing-employee and insider matters

    A laptop returned by a departing employee is often the only copy of what happened. Imaging it before IT reissues the machine is frequently the difference between a provable case and an inference.

  • Challenges to an opposing party's collection

    Where the other side collected without forensic method, we examine what was produced, identify what the method could not have captured, and support a motion to compel a defensible re-collection.

  • Authentication disputes at trial

    When an exhibit's provenance is contested, the acquisition record is the answer. We testify to how the evidence was obtained and why the copy in evidence is what it purports to be.

Forensic Imaging & Chain of Custody — frequently asked questions

What is forensic imaging, and how is it different from copying files?

Copying files reproduces the files a filesystem chooses to show you. A forensic image captures the storage medium itself, including unallocated space, file slack, and deleted content that no longer appears in any directory listing — plus the metadata that establishes when files were created, modified, and accessed. Copying also updates access timestamps on the source, altering the very evidence you are trying to preserve. That difference is usually where a case is won or lost: the deleted file and the timestamp are frequently the proof.

What is a write blocker and why does it matter?

A write blocker sits between the examiner's system and the source media and physically or logically prevents any write operation reaching it. Without one, simply attaching a drive to a running computer can cause the operating system to write to it — mounting volumes, updating timestamps, creating recovery files. Any of those changes the hash, and a changed hash invites the argument that the examiner altered the evidence. Using a write blocker, and documenting that you did, removes the argument.

How does hashing prove an image has not been altered?

A hash function reduces the entire contents of a drive to a fixed-length value, and changing a single bit produces a completely different value. We compute a hash at acquisition, re-verify it after imaging, and re-verify again whenever a working copy is made. When those values match, an examiner can state that the image analyzed in the lab is identical to what was acquired from the device — and that statement is checkable by anyone with the same image.

What happens if the chain of custody is broken?

A gap does not automatically make evidence inadmissible, but it shifts the argument from what the evidence shows to whether it can be trusted, and it is the first place a competent opposing expert will probe. Courts weigh the gap against the other indicia of reliability, and a verified hash can go a long way toward closing it. The practical answer is that an unbroken, contemporaneous record costs very little to maintain and is expensive to reconstruct after the fact.

Can you image a device that is encrypted?

Often, but the result differs. A physical image of an encrypted drive without the key yields ciphertext, which preserves the data but cannot be analyzed. Where credentials or keys are available we acquire in a decrypted state; where they are not, we may perform a live or logical acquisition from the running system. Each approach captures a different scope, and we document which was used and what it excludes rather than presenting a logical acquisition as a full physical image.

How is cloud data preserved when there is nothing to write-block?

Cloud evidence lives on infrastructure you cannot touch, so preservation shifts from imaging hardware to controlling and documenting the export. We use the provider's supported collection paths, capture the server-side metadata that evidences completeness, record the exact query parameters and date ranges used, and hash the resulting export. The defensibility comes from reproducibility: another examiner running the same request should obtain the same set.

How do imaging and chain of custody support authentication in court?

Federal Rule of Evidence 901(b)(9) allows authentication by describing a process or system and showing it produces an accurate result — which is what a documented imaging methodology is. Rule 902(14) goes further, letting data copied from an electronic device be self-authenticating when it is identified by a hash and certified by a qualified person, which can remove the need for live foundation testimony entirely. Both depend on having done the acquisition properly and written it down at the time.

More Digital Forensics questions answered →

Digital Forensics experts who testify to this work

Full expert panel →
  • J-Michael Roberts, Senior Director, Law & Forensics

    J-Michael Roberts

    Senior Director

    Digital Forensics · Incident Response · Malware Reverse Engineering

  • Digital Forensics · Expert Witness Testimony · Incident Response

  • Roland Cloutier, Expert Consultant, Law & Forensics

    Roland Cloutier

    Expert Consultant

    Incident Response · Expert Witness Testimony

Our experts serve as court-appointed special masters, forensic neutrals, and arbitrators — 55 appointments are listed by matter and citation.

Ready to discuss your matter?

Submit a case