Digital Evidence Sources

Source categories, preservation risks, and information required at intake for preservation and forensic data acquisition under written authorization and within an approved scope.

Mobile devices

Sources

  • iPhone and Android devices
  • iPad and other tablets
  • Device backups and associated account exports

Preservation Risks

  • Replacement, reset, upgrade, trade-in, or return to a carrier or employer
  • Passcode, linked-account, or device-configuration changes
  • Ongoing use that may alter message or application data

Information Required at Intake

  • Device model, condition, and active-use status
  • Related backups and linked accounts
  • Turnover, travel, trade-in, and access deadlines

Computers and external media

Sources

  • Windows and macOS computers
  • External drives, USB media, and memory cards
  • Local backups, disk images, and transferred archives

Preservation Risks

  • Reassignment, reimaging, or return of equipment
  • Hardware instability or storage-media failure
  • Uncontrolled copying or incomplete transfer records

Information Required at Intake

  • Device type, operating system, and known storage condition
  • On-site handling or transfer requirements
  • Related external media, backups, and shared folders

Email and cloud repositories

Sources

  • Microsoft 365, Exchange, and Google Workspace mailboxes
  • OneDrive, SharePoint, Google Drive, and Dropbox repositories
  • Administrative exports and account archives

Preservation Risks

  • Mailbox turnover, deprovisioning, or account closure
  • Repository restructuring or permission changes
  • Incomplete exports resulting from undefined account, custodian, date, folder, or repository scope

Information Required at Intake

  • Provider, account owners, custodians, and access authority
  • Accounts, folders, repositories, and date parameters within scope
  • Available acquisition or export method
  • Required output format and delivery method

Messaging and collaboration platforms

Sources

  • Text messages and messaging-app data
  • Slack, Microsoft Teams, and other authorized collaboration exports
  • Chat histories, attachments, and shared files

Preservation Risks

  • Message deletion, retention limits, or user-access changes
  • Incomplete exports omitting attachments, reactions, or conversation context
  • Screenshot-only transfers without source identification, metadata, or receipt records

Information Required at Intake

  • Platform, account owners, custodians, and access authority
  • Accounts, conversations, channels, and date parameters within scope
  • Available export method and required output format
  • Attachments, shared files, and user-access records within scope

Logs, backups, and account records

Sources

  • Administrative logs and access-history records
  • Backup sets and account archives
  • Provider-generated account and transfer records

Preservation Risks

  • Short log-retention windows
  • Provider-side changes affecting record or export availability
  • Incomplete association between logs, backups, and source inventory

Information Required at Intake

  • Provider or system, accounts, record types, and date parameters within scope
  • Access authority and available retrieval or export method
  • Relationship to a device, custodian, or account event
  • Retention limits and administrative dependencies affecting timing

Transferred materials and third-party exports

Previously copied or exported materials require receipt documentation that distinguishes transferred material from direct-source preservation.

Sources

  • Portal downloads and vendor exports
  • Screenshots, PDFs, and image sets
  • Media and archives received from another stakeholder

Preservation Risks

  • Unclear origin or incomplete transfer history
  • Failure to distinguish transferred material from direct-source preservation
  • Screenshot-only materials without source, metadata, or transfer context

Information Required at Intake

  • Original creator or exporting party
  • Original-source availability
  • Existing transfer, receipt, and inventory records

Method Selection

  • Source type, current condition, location, and operational state
  • Volatility, retention limits, and continued-use constraints
  • Authority, access path, and available acquisition or export method
  • Expected deliverables, verification records, return requirements, and delivery method

Matter Intake

  • Primary contact and authorization
  • Account owners, device users, custodians, source list, and current source availability
  • Approved scope and preservation deadlines
  • Authorization for account and repository access
  • Transfer and delivery methods
  • Return instructions and expected deliverables