Evidence Acquisition Fundamentals
Acquisition is the bridge between the existence of a digital trace and its usability as evidence. It is where the philosophical principles from your Core Principles of Forensic Science and the procedural constraints of your The 5 Principles of Digital Forensics become technical requirements.
You cannot find the needle until you preserve the haystack without altering it.
1. Live vs. Dead Acquisition
The investigator must choose whether to capture evidence from a running system or a powered-off system. This decision is a direct tension between Progressive Change and Integrity.
| State | Risk | Benefit |
|---|---|---|
| Live | You modify the system by interacting with it (violates perfect Integrity). | You preserve volatile evidence—RAM, open network connections, decrypted volumes—that dies if you shut down (honors Progressive Change). |
| Dead | You lose volatile data forever. | You get a static, unchanging target with minimal interaction risk. |
Key decision: If the case hinges on memory-resident malware, encryption keys, or active network sessions, live acquisition is necessary. If the case is about historical file artifacts, dead acquisition is cleaner and more defensible.
2. Imaging: Creating the Forensic Copy
You never work on the original evidence. You create a bit-for-bit forensic image—a complete duplicate of every bit on the source media.
Common Forensic Formats
| Format | Properties | Use Case |
|---|---|---|
| Raw (dd) | Uncompressed, no metadata, universally supported. | Simplicity, compatibility, but requires separate hash logs. |
| E01 (Expert Witness) | Compressed, checksums embedded, supports metadata (case number, examiner). | Industry standard; self-contained integrity checks. |
| AFF (Advanced Forensic Format) | Open source, compression, metadata, and crypto-hashes built-in. | Cross-platform, open standard. |
The format you choose becomes part of your Defensibility—prosecutors and opposing counsel will ask why you used it.
3. Hashing as Verification
Hashing is how you mathematically prove Integrity. It is not optional; it is the mechanism that makes integrity demonstrable.
The Standard Workflow
- Hash the original media before imaging (e.g., SHA-256).
- Hash the image immediately after creation.
- Verify the image hash matches the original hash.
- Document everything in your notes and chain of custody.
If the hashes match, you have proof that the image is an exact duplicate. If the hashes differ, something went wrong—bad sectors, a write blocker failure, or media corruption.
Hash collision note: MD5 is still used for speed in some contexts, but SHA-256 is preferred for Defensibility because it is cryptographically stronger.
4. Write Protection
Any interaction with original evidence risks modification. Write protection ensures you cannot accidentally alter the source.
- Hardware write blockers: External devices that sit between the source media and the acquisition workstation. They are preferred for Defensibility because they are independent and auditable.
- Software write blockers: OS-level controls that prevent write commands. Less preferred because they rely on the host system, which itself may modify the source during detection/automount.
Best practice: Document the exact write blocker model, firmware version, and testing procedure in your notes.
5. Chain of Custody as Workflow
Chain of custody is the audit trail that transforms a hard drive into admissible evidence. It is not a single form—it is a continuous thread.
What to Document
- Who collected the evidence.
- When and where it was collected.
- What tools and methods were used.
- Hash values at each transfer point.
- Every person who accessed it, when, and why.
- Storage conditions (secure, tamper-evident, climate-controlled).
A gap in chain of custody destroys Defensibility. Even if the evidence itself is perfect, a missing signature or unlogged transfer can render it inadmissible.
Connection to Your Principles
| Principle | How Acquisition Enforces It |
|---|---|
| Integrity | Hashing, write blockers, and forensic images. |
| Lawfulness | Proper authority, consent, or warrant before touching the media. |
| Reproducibility | Documented tools, settings, and hashes allow another examiner to re-image and compare. |
| Defensibility | Chain of custody, tool validation, and standard operating procedures. |
| Objectivity | The acquisition method is chosen based on the evidence type, not the investigator’s convenience. |
Before You Move Forward
Before diving into artifact analysis or memory forensics, you should be able to answer these questions for any scenario:
1. Would this case require live or dead acquisition? Why?
2. What format would you image in, and what metadata would you include?
3. What hash algorithm would you use, and where would you store the hash values?
4. What write blocker would you use, and how would you document it?
5. If asked in court, could you explain why your method preserved the integrity of the evidence?
Acquisition is not glamorous, but it is the foundation upon which every other forensic skill depends. A brilliant artifact analyst is useless if the image they analyzed was created without integrity controls.