Real evidence is a physical, tangible object that played a relevant role in the event being investigated. It is the kind of evidence a jury can see and touch, such as the murder weapon, a fingerprint, or a signed paper contract.
In digital forensics, real evidence typically refers to the physical hardware involved in an incident, rather than the data stored on it. Examples include:
- The physical hard drive or SSD
- A USB device
- The computer itself, including chassis, keyboard, and peripherals
- The suspect's phone or tablet
The data stored on these devices is not usually considered real evidence because it is intangible and must be interpreted through abstraction layers, filesystem protocols, and forensic tools. Instead, digital data is usually treated as Digital Evidence, Best Evidence, or Circumstantial Evidence.
Because real evidence is physical, it requires a strong chain of custody and must be preserved without alteration or tampering to be admissible in court.
Source: Network Forensics: Tracking Hackers through Cyberspace, §1.3.1.