Digital Evidence Sources
Source categories, preservation risks, and information required at intake for preservation and forensic data acquisition under written authorization and within an approved scope.
Mobile devices
Sources
- iPhone and Android devices
- iPad and other tablets
- Device backups and associated account exports
Preservation Risks
- Replacement, reset, upgrade, trade-in, or return to a carrier or employer
- Passcode, linked-account, or device-configuration changes
- Ongoing use that may alter message or application data
Information Required at Intake
- Device model, condition, and active-use status
- Related backups and linked accounts
- Turnover, travel, trade-in, and access deadlines
Computers and external media
Sources
- Windows and macOS computers
- External drives, USB media, and memory cards
- Local backups, disk images, and transferred archives
Preservation Risks
- Reassignment, reimaging, or return of equipment
- Hardware instability or storage-media failure
- Uncontrolled copying or incomplete transfer records
Information Required at Intake
- Device type, operating system, and known storage condition
- On-site handling or transfer requirements
- Related external media, backups, and shared folders
Email and cloud repositories
Sources
- Microsoft 365, Exchange, and Google Workspace mailboxes
- OneDrive, SharePoint, Google Drive, and Dropbox repositories
- Administrative exports and account archives
Preservation Risks
- Mailbox turnover, deprovisioning, or account closure
- Repository restructuring or permission changes
- Incomplete exports resulting from undefined account, custodian, date, folder, or repository scope
Information Required at Intake
- Provider, account owners, custodians, and access authority
- Accounts, folders, repositories, and date parameters within scope
- Available acquisition or export method
- Required output format and delivery method
Messaging and collaboration platforms
Sources
- Text messages and messaging-app data
- Slack, Microsoft Teams, and other authorized collaboration exports
- Chat histories, attachments, and shared files
Preservation Risks
- Message deletion, retention limits, or user-access changes
- Incomplete exports omitting attachments, reactions, or conversation context
- Screenshot-only transfers without source identification, metadata, or receipt records
Information Required at Intake
- Platform, account owners, custodians, and access authority
- Accounts, conversations, channels, and date parameters within scope
- Available export method and required output format
- Attachments, shared files, and user-access records within scope
Logs, backups, and account records
Sources
- Administrative logs and access-history records
- Backup sets and account archives
- Provider-generated account and transfer records
Preservation Risks
- Short log-retention windows
- Provider-side changes affecting record or export availability
- Incomplete association between logs, backups, and source inventory
Information Required at Intake
- Provider or system, accounts, record types, and date parameters within scope
- Access authority and available retrieval or export method
- Relationship to a device, custodian, or account event
- Retention limits and administrative dependencies affecting timing
Transferred materials and third-party exports
Previously copied or exported materials require receipt documentation that distinguishes transferred material from direct-source preservation.
Sources
- Portal downloads and vendor exports
- Screenshots, PDFs, and image sets
- Media and archives received from another stakeholder
Preservation Risks
- Unclear origin or incomplete transfer history
- Failure to distinguish transferred material from direct-source preservation
- Screenshot-only materials without source, metadata, or transfer context
Information Required at Intake
- Original creator or exporting party
- Original-source availability
- Existing transfer, receipt, and inventory records
Method Selection
- Source type, current condition, location, and operational state
- Volatility, retention limits, and continued-use constraints
- Authority, access path, and available acquisition or export method
- Expected deliverables, verification records, return requirements, and delivery method
Matter Intake
- Primary contact and authorization
- Account owners, device users, custodians, source list, and current source availability
- Approved scope and preservation deadlines
- Authorization for account and repository access
- Transfer and delivery methods
- Return instructions and expected deliverables