How an examination actually runs, from preservation and imaging through analysis, reporting and testimony. Adapted from the original evestigate.com library, with method and reporting limits clarified October 7, 2026.
Resource
The Digital Forensics Process
Plan
Start with the question, lawful authority, relevant sources and deadline. GDF works with the technical owners and retained counsel to distinguish preservation, acquisition, processing, analysis and reporting. The plan identifies access assumptions, data that may disappear, operational constraints and conditions for expanding the work.
Acquire
The appropriate method may be a forensic disk image, a targeted endpoint collection or an authorized provider export. Record device or account identifiers, condition, collection time, tools and settings, filters and transfers. Integrity checks and handling records help explain the acquired data. A cloud export or live acquisition has limits that differ from a complete disk image; acquisition cannot assure admissibility or recovery of every artifact.
Extract
Identify relevant files, messages, application records, logs and structured data within the acquired sources. Access can be limited by encryption, overwriting, retention, hardware damage or unsupported formats. Select and validate methods suited to the source. Custom processing may be useful when ordinary tools do not answer the question, but its assumptions and checks must be documented.
Analyze
Correlate relevant sources to test the disputed events. A timestamp, account name or isolated document rarely resolves every question by itself. Check time conventions, processing changes, alternative explanations and missing records. Distinguish observed artifacts from interpretation, and corroborate material conclusions where the available evidence permits.
Report
The agreed report can include source inventories, methods, relevant records, timelines, charts and exhibits. Findings should be traceable to the underlying data and state material uncertainty. When retained for testimony, the examiner explains the methods and conclusions; counsel addresses legal use and the court decides admissibility and weight. Neither reporting nor testimony guarantees a favorable outcome.
Experience relevant to the source
Select a team for the actual systems and questions in the assignment. Discuss the proposed examiner's relevant experience, available access, tool support and expected deliverables. Public case studies describe selected work; they do not promise the same result or establish competence for every device.
Confidentiality and documented methods
Agree secure handling, access restrictions, reporting recipients and retention for the assignment. Commercial and proprietary tools may be used alongside documented custom processing. Reproducibility depends on explaining relevant methods, inputs, settings and validation, not on a claim that no proprietary software is ever involved. Private material should be shared through the agreed secure channel.
Technical reference: NIST forensic-method guidance and its scope (opens in a new tab). For a collection decision, see Common Digital Evidence Mistakes.
Related
Related services
Talk with an examiner
Discuss the matter and the next step.
Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.
24/7 hotline: 1-800-868-8189