Phone:

Hidden from the page source until you click: friction against scrapers, not a guarantee.

Email:

[email protected]

Digital Forensics Guide

6. Custody and contingencies

An unbroken custody record and a plan for when things go wrong. This chapter covers labelling, sealing and hand-overs, and the on-site procedures for encrypted devices, failing media and imaging failures.

In this chapter

  1. Chain of custody
  2. Contingency procedures on site

10. Documentation

Chain of custody

Chain of custody is the unbroken record of who has had the evidence, from seizure to presentation. Any gap invites the argument that the evidence could have been altered while nobody was watching.

Record every hand-over

For each item of evidence, keep a form that records:

  • A unique evidence reference (for example, case number, item number: CASE-2026-014/03).
  • A description: make, model, serial number, capacity, distinguishing marks.
  • Where and when it was found, and by whom.
  • Every transfer: from whom, to whom, date, time, purpose, and both signatures.
  • Every examination: who, when, what was done, and whether the seal was broken and re-applied (with old and new seal numbers).
  • Storage location at each stage.

Label and seal

  • Label each item with its evidence reference before it leaves the scene. Label cables and adaptors too, and keep them with their device.
  • Seal each item in a tamper-evident bag. Write the seal number, the date, the time and your name on the form and across the seal.
  • Photograph the sealed item with the label visible.
  • Digital evidence gets the same treatment in digital form: the file's hash, the system it was exported from, the person who exported it and the time. A memory image, a ddrescue map file and a carved fragment are each items of evidence with their own entry.

Maintain an auditable trail

The test is simple: could a stranger, holding only your paperwork, reconstruct where every item has been and who has touched it, hour by hour, and check each claim against a signature, a seal number or a hash? If the answer is yes, the chain holds.

Example. The seized workstation is driven to the laboratory by a colleague who signs for it at 16:40, logs it into the evidence store at 17:55 and signs it out to the examiner at 09:05 the next morning. The examiner records the unbroken seal number before breaking it, images the drives, re-seals the workstation with a new seal and records both numbers. That is a complete chain. "I left it on my desk overnight" is not.

11. Preservation, acquisition

Contingency procedures on site

Things go wrong on site. What separates a good examiner from a lucky one is having decided in advance what to do when they do.

Encrypted devices

  • If the device is on and unlocked, keep it that way: prevent sleep if you can do so without typing (connecting mains power is usually safe), capture memory, record the encryption status, and take a logical copy of any mounted encrypted volume before powering off. Then image the encrypted disk physically.
  • If the device is off or locked, do not guess passwords. Repeated failures can trigger lockouts or wiping. Image the encrypted drive as it is (the image is valid evidence and can be decrypted later) and pursue keys through the legitimate sources in section 12.
  • Record every encryption indicator you see, including the exact prompt text and any recovery key identifier shown.

Damaged or unstable storage

  • A drive that clicks, spins up and down, or is very slow to read is failing. Stop, photograph, and switch to fault-tolerant acquisition (section 8) or escalate, rather than repeatedly retrying.
  • Physically damaged devices (water, fire, crushed phones) go to a specialist recovery laboratory in an anti-static bag with a note of the conditions they were found in. Do not power them on.

When imaging fails

  • Record the failure exactly: tool, version, error text, time, how far it got.
  • Check the boring causes first: cable, adaptor, power supply, write blocker compatibility, the drive's interface, available space on the destination.
  • Try a different tool or a different workstation before concluding the source is at fault.
  • If a full physical image is impossible, take the best acquisition you can (a partial image with a map, a logical copy, targeted collection of key folders) and document clearly that it is partial and why.
  • Never "repair" the source drive to make it image. Any repair changes evidence.

Escalate to specialist recovery

Escalate when a device is physically damaged, when a drive is deteriorating, when the storage technology is outside your experience (unusual RAID sets, self-encrypting drives, phones that resist standard extraction) or when the stakes are high enough that a single failed attempt is unacceptable. Escalation is not failure; attempting recovery beyond your competence and destroying the evidence is.

Example. A USB stick from the desk drawer is not recognised by the imaging workstation. The examiner tries a second cable and a second port, records both attempts, photographs the stick and its controller markings, seals it and sends it to a recovery laboratory with the notes. The laboratory reads the flash memory directly. Had the examiner prised the casing open to "check the connection", that outcome would have been in doubt.