Resource

The Digital Forensics Process

Bagged hard drive beside a forensic write blocker.

How an examination actually runs, from preservation and imaging through analysis, reporting and testimony. Adapted from the original evestigate.com library, with method and reporting limits clarified October 7, 2026.

Plan

Start with the question, lawful authority, relevant sources and deadline. GDF works with the technical owners and retained counsel to distinguish preservation, acquisition, processing, analysis and reporting. The plan identifies access assumptions, data that may disappear, operational constraints and conditions for expanding the work.

Acquire

The appropriate method may be a forensic disk image, a targeted endpoint collection or an authorized provider export. Record device or account identifiers, condition, collection time, tools and settings, filters and transfers. Integrity checks and handling records help explain the acquired data. A cloud export or live acquisition has limits that differ from a complete disk image; acquisition cannot assure admissibility or recovery of every artifact.

Extract

Identify relevant files, messages, application records, logs and structured data within the acquired sources. Access can be limited by encryption, overwriting, retention, hardware damage or unsupported formats. Select and validate methods suited to the source. Custom processing may be useful when ordinary tools do not answer the question, but its assumptions and checks must be documented.

Analyze

Correlate relevant sources to test the disputed events. A timestamp, account name or isolated document rarely resolves every question by itself. Check time conventions, processing changes, alternative explanations and missing records. Distinguish observed artifacts from interpretation, and corroborate material conclusions where the available evidence permits.

Report

The agreed report can include source inventories, methods, relevant records, timelines, charts and exhibits. Findings should be traceable to the underlying data and state material uncertainty. When retained for testimony, the examiner explains the methods and conclusions; counsel addresses legal use and the court decides admissibility and weight. Neither reporting nor testimony guarantees a favorable outcome.

Experience relevant to the source

Select a team for the actual systems and questions in the assignment. Discuss the proposed examiner's relevant experience, available access, tool support and expected deliverables. Public case studies describe selected work; they do not promise the same result or establish competence for every device.

Confidentiality and documented methods

Agree secure handling, access restrictions, reporting recipients and retention for the assignment. Commercial and proprietary tools may be used alongside documented custom processing. Reproducibility depends on explaining relevant methods, inputs, settings and validation, not on a claim that no proprietary software is ever involved. Private material should be shared through the agreed secure channel.

Technical reference: NIST forensic-method guidance and its scope (opens in a new tab). For a collection decision, see Common Digital Evidence Mistakes.

Related

Related services

Talk with an examiner

Discuss the matter and the next step.

Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.