Independent technical practice

Resources

Reference material written for people who have to work with digital evidence without being forensic examiners themselves.

Bagged hard drive beside a forensic write blocker.

Reference library

Digital evidence guides and glossaries

  • Digital Forensics FAQ

    Answers to the questions clients ask before an engagement: how examinations work, when to involve an examiner, and how evidence is preserved.

  • Cybersecurity Acronym Glossary

    The acronyms used across forensics, incident response, operational technology and regulatory practice, expanded and explained in plain language.

  • Cybercrime Terminology

    Plain-language definitions of the attack techniques, tooling and terminology that appear in incident reports, pleadings and breach notifications.

  • Common Digital Evidence Mistakes

    What most often damages digital evidence before an examiner ever sees it, and what to do instead when a matter is first identified.

  • The Digital Forensics Process

    A step-by-step walkthrough of an examination, from preservation and imaging through analysis, reporting and testimony.

These references are preserved from the original evestigate.com library. They describe practice as it stood when they were written; current engagement scope is set case by case.

Talk with an examiner

Discuss the matter and the next step.

Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.