Digital Evidence Readiness
Would your evidence hold up in court?
When an investigation, a dispute or a breach lands on your desk, the evidence you collect is only as strong as the process behind it. Opposing counsel does not attack the data; they attack the handling. This self-audit walks the evidence lifecycle the way an examiner and a cross-examining lawyer both would, scores your readiness and explains what each control means and why it decides admissibility. Built by court-qualified examiners, digital forensics since 2006.
This is a readiness self-assessment, not legal advice. Admissibility is decided by a court on the facts of each matter. These are the controls that make evidence defensible, not a guarantee of any outcome.
Digital Evidence Readiness Self-Audit · Sherlock Forensics · a self-assessment, not legal advice.
1. Evidence Identification and Scope
0/5You can list every system, account, device and cloud service that may hold relevant data.
You cannot preserve what you have not identified. Missed sources such as a personal device, a SaaS mailbox or a backup become the "what else did you not look at?" question in cross-examination.
You know which data is transient and will be lost first (RAM, logs, cloud tenancy, ephemeral messaging).
Volatile data has a clock. An incident response that starts with a disk image while the memory and live logs age out has already lost evidence that cannot be recovered.
Scope is documented and defensible (why these sources, why not others).
Over-collection invites privacy and proportionality challenges. Under-collection invites spoliation claims. The written rationale is what defends both.
You distinguish evidence you must PRESERVE from data you will ANALYZE.
Preservation is a legal duty that can attach before you analyze anything. Conflating them delays the one step a court will not forgive you for skipping.
Personal-device and BYOD data in scope has a lawful basis to collect.
Consent or lawful authority is the line between evidence and an unlawful search. Get it wrong and the evidence is excluded regardless of what it shows.
2. Preservation and Legal Hold
0/5A legal hold can be issued and tracked the day a matter is reasonably anticipated.
The duty to preserve attaches at "reasonably anticipated", not at filing. Auto-deletion that runs after that point is spoliation, and courts sanction it.
Auto-deletion, retention rules and journaling are paused for held custodians.
A 30-day mailbox purge or a rotating log will quietly destroy evidence while the hold sits unread. Preservation means stopping the shredder, not just labelling the box.
Preservation is verified, not assumed (you confirm the data still exists after the hold).
"We issued a hold" is not the same as "the data survived". Confirming the held data is intact is the difference between a defensible record and a hope.
Cloud and third-party data is preserved before tenancy or contracts lapse.
When a service is cancelled or a vendor changes, the data can vanish on their schedule, not yours. Preserve exports while you still control access.
Original evidence is never worked on directly. You preserve a master and work on copies.
Every action on an original risks altering it. A preserved master plus verified working copies is the foundation every later step relies on.
3. Forensic Collection Integrity
0/6Collections use write-blocking or read-only acquisition so the source is never modified.
If the act of collecting changes the source, the defence is that you may have changed the evidence. Read-only acquisition removes that argument.
Every acquired item is hashed (SHA-256) at collection and the hash is recorded.
The hash is the fingerprint that proves the copy equals the source and has not changed since. No hash, no way to prove integrity.
Hashes are re-verified before analysis and before it goes to court.
A hash captured once and never rechecked proves nothing about the intervening months. Re-verification proves the evidence is byte-for-byte what you collected.
Collection is documented: who, what, when, how, tool plus version.
A competent tool used by an undocumented process is still challengeable. The record of exactly how it was collected is what a court weighs.
Where deleted or damaged data is recovered, the method and its limits are stated.
Overclaiming recovery ("we got everything back") collapses under cross. Stating what was recovered, how and what could not be is what makes the recovery credible.
You capture the acquisition context the tool records (device state, access decisions, what was and was not reachable).
The record of why you could not read something is often more defensible than a clean result. It shows a documented, honest process rather than a cherry-picked one.
4. Chain of Custody
0/4Every transfer of evidence is logged (from whom, to whom, when, why).
A single undocumented gap such as "where was this for those three days?" is enough to exclude an exhibit. The custody log closes that gap.
Evidence storage is access-controlled and the access is auditable.
If anyone could have touched the evidence, opposing counsel will argue someone did. Controlled, logged storage answers that before it is asked.
Custody records tie to the hash, so the item in the log is provably the item in hand.
A custody log for "a hard drive" proves little. A log tied to a SHA-256 proves it is THAT drive, unchanged.
The chain survives personnel changes (it is a record, not one person's memory).
If the only person who can vouch for custody leaves or is unavailable, an oral chain evaporates. A written, transferable record does not.
5. Email and Archive Evidence (PST / OST / MSG)
0/5Email is examined from the archive, not from a live mailbox that keeps changing.
A live mailbox mutates as mail arrives and rules fire. A preserved PST or OST is a fixed point you can hash, examine and reproduce.
You can read PST, OST and MSG without Outlook altering the source.
Opening evidence mail in Outlook can mark it read, fire rules or reindex, all silent changes to an exhibit. Read-only examination avoids it. This is what Sherlock Forensics PST Viewer does.
Message authentication is checked (SPF, DKIM, DMARC, full headers, transport path).
The headers are where spoofing, forgery and the true send path live. A body without its authenticated headers is a claim, not evidence.
Timestamps are handled in a stated, consistent timezone (originals unchanged).
A timeline that silently mixes UTC and local time misleads the reader and invites attack. Stating the zone and never altering the original stamp keeps it defensible.
Deleted and recovered items are labelled as recovered, with their limits.
A recovered message presented as if it were live overstates certainty. Labelling recovery and what may not have survived is what a court trusts.
6. Mobile Device Evidence
0/5Collection is consent-based or under lawful authority, and that basis is recorded.
A phone collected without a lawful basis is an unlawful search and the evidence is excluded no matter how relevant. The recorded basis is the defence.
You understand what a logical acquisition can and cannot reach on modern devices.
On modern Android and iOS, encryption and TRIM mean truly deleted files are gone for everyone, and some app data needs full-filesystem access. Claiming more than a logical acquisition delivers invites an easy rebuttal.
Recovered records (deleted rows, gaps) are distinguished from live data and labelled.
A deleted message recovered from a database free-list is real, but presenting it as if it were live overstates it. The honest label is what survives challenge.
Encrypted content is decrypted with a lawful key, never cracked.
Decrypting with a provided key is sound. Cracking a password to get in raises a Daubert and a lawful-access problem. The method matters as much as the result.
Mobile findings can be reproduced from the same extraction by another examiner.
If only your tool, on your machine, produces the finding, it is not reproducible, and reproducibility is a pillar of admissibility.
7. Analysis and Reporting
0/5Reports state the tool, version and method for every finding.
A finding with no stated method cannot be tested, and untestable findings are weak evidence. The method is what makes a result reproducible and admissible.
Findings are reproducible: another examiner, same inputs, same result.
Reproducibility is a core Daubert factor. If the result cannot be reproduced, the technique itself is open to challenge.
Every reported artifact carries its own integrity hash.
Per-item hashing lets anyone confirm the exhibit in the report is the exhibit that was examined, not a later edit.
Reports state limits and what was NOT found or not reachable.
A report that only shows hits reads as cherry-picked. Stating the negatives and the limits is what makes the positives credible.
Timestamps, timezones and units are consistent and explained across the report.
Inconsistent time or units is the easiest thing to attack and the fastest way to lose a jury's trust in the whole report.
8. Legal Defensibility and Expert Readiness
0/4A qualified examiner can explain and defend the method under cross-examination.
Evidence rarely fails on the data. It fails on whether someone can stand behind the process. An examiner who can explain every step is the real deliverable.
Methods meet a recognised standard (reliable, tested, reproducible, the Daubert factors).
Courts gate expert evidence on reliability. A method that is tested, reproducible and documented clears that gate. An ad-hoc one may not.
Disclosure obligations are met (the other side can examine your process and exhibits).
Evidence produced from a black box invites exclusion. A process the other side can inspect is a process a court will accept.
The organisation knows when to bring in a qualified examiner rather than improvise.
The most common way evidence dies is a well-meaning IT team touching it first. Knowing the line and who to call protects the case before the first mistake.
What your score means
- At Risk (0-40%): Evidence is likely challengeable. These are gaps a competent opponent will find.
- Developing (41-70%): The basics exist but the chain has weak links.
- Defensible (71-90%): A sound process. Tighten the last gaps.
- Court-Ready (91-100%): A process built to survive cross-examination.
Gaps in this audit are exactly where cases are won and lost. Sherlock Forensics builds the tools that close them. PST Viewer for court-ready email examination, Android Acquirer and iPhone Analyzer for consent-based mobile collection and Recover for what others miss. We also provide court-qualified examiners when a matter needs to hold up. Digital forensics since 2006.
See the forensic tools Talk to an examinerEmail me my results plus the companion remediation playbook
Optional. Get a copy of this audit and a short next-steps playbook for closing the gaps. No spam, one email.
This self-audit is general guidance for digital evidence handling and is not legal advice. Admissibility standards and procedural rules vary by jurisdiction. Confirm the requirements for your matter with counsel.
