Digital forensics
Evidence preservation & chain of custody
A finding is only as robust as its documentation. This page sets out what AQON INTELLIGENCE records from the arrival of the material to the technical assessment, and where the limits of that record lie.
Documentation
What is recorded during an examination
The record is kept so that a third party with the necessary expertise can follow how a result came about.
Intake and initial condition
The time of handover, the external condition of the material, its operating state and any existing markings, seals or damage are recorded.
Unambiguous identification
Every device and data storage medium receives its own identifier. Serial numbers, IMEI, model designation and storage capacity are recorded so that later statements can be attributed to a specific object.
Handovers and access
Who took custody of the material and when, and which persons had access to copies, is logged. Access is limited to what the examination requires.
Type and scope of acquisition
It is documented whether a physical, file-system or logical acquisition was possible, which areas were captured and which could not be reached technically.
Integrity verification
Where technically meaningful, hash values are formed over images and verified again after acquisition. For systems that must be acquired while running, the limited reproducibility is stated openly.
Systems and versions used
The hardware, software and relevant version states are noted, because results can depend on the generation of the tool used.
Limits
What documentation cannot establish
A documented chain of custody shows how material was handled. It does not by itself prove who operated a device, and it cannot restore data that were never written or have been overwritten.
Where an acquisition is incomplete, where a device only permits limited access, or where a result cannot be reproduced, this is stated in the report rather than smoothed over. The technical findings are assessed by an expert and recorded in a formal expert report.
Where a concrete examination of computers, servers, storage media, logs or account activity is required, the IT forensic examination covers that work as an instructable service.
