Forensics

The following documents have completed the required comment period and are considered final releases.  All documents are considered living documents - updates are periodically made at which time they are released for an additional comment period if changes were substantive.  All versions are formally archived and only the most recent applicable version is found here.

SWGDE encourages stakeholder participation in the preparation of documents. Suggestions for modifications are welcome and must adhere to all requirements as stated in our Disclaimer and Redistribution policies, which are attached to the front of every document.  

Submit Electronic Request for Modifications 

SWGDE also encourages the use and redistribution of our documents.  The Disclaimer and Redistribution policies (also included in the cover pages to each document) also establish what is considered SWGDE's Intellectual Property.  The policies for the Use and Redistribution of our information and documents is also defined therein.  

Submit Notice of Use/Redistribution

2023-12-18 SWGDE Recommendations for Cell Site Analysis (17-F-001-2.0) 

2023-09-20 SWGDE Best Practices for Chromebook Acquisition and Analysis (22-F-002-1.0) 

2023-06-15 SWGDE Best Practices for Computer Forensic Acquisitions (17-F-002-2.0) 

2023-03-31 SWGDE Linux Technical Notes (16-F-001-2.0) 

2022-09-22 SWGDE Best Practices for Remote Collection of Digital Evidence from a Networked Computing Environment (22-F-003-1.0) 

2022-09-22 SWGDE Best Practices for On-Scene Identification, Seizure, and Preservation of Internet of Things (IoT) Devices (22-F-001-1.0) 

2022-09-22 SWGDE Best Practices for Obtaining Google Reverse Location Data for Investigative Purposes (22-F-004-1.2) 

2022-01-13 SWGDE Best Practices for Vehicle Infotainment and Telematics Systems v3.0 

2022-01-13 SWGDE Best Practices for Obtaining Google Reverse Location Data for Investigative Purposes v1.1 

2022-01-13 SWGDE Best Practices for Drone Forensics v1.0 

2022-01-13 SWGDE Best Practices for Acquiring Online Content v1.0 

2020-09-17 SWGDE Best Practices for Digital Evidence Acquisition from Cloud Service Providers v1.0 

2020-09-17 SWGDE Best Practices for Examining Magnetic Card Readers v3.1 

2020-09-17 SWGDE Best Practices for Mobile Device Evidence Collection & Preservation Handling and Acquisition v1.2 

2020-09-17 SWGDE Best Practices for Mobile Device Forensic Analysis v1.0 

2020-09-17 SWGDE Core Competencies for Embedded Device Forensics v1.0 

2020-09-17 SWGDE Technical Notes on Internet of Things Devices v1.0 

2020-09-17 SWGDE Test Method for Bluetooth® Module Extraction and Analysis v1.1 

2020-09-17 SWGDE Test Method for Skimmer Forensics - Analog Devices v1.0 

2020-09-17 SWGDE Test Method for Skimmer Forensics - Digital Devices v1.0 

2018-11-20 SWGDE Best Practices for Portable GPS Devices v1.2 

2018-07-11 SWGDE Best Practices for Digital Evidence Collection 

2018-07-11 SWGDE Best Practices for Computer Forensic Examination 

2017-02-21 SWGDE Windows 8 and 8.1 Tech Notes 

2017-02-21 SWGDE Tech Notes regarding Chip-off via Material Removal 

2017-02-21 SWGDE Best Practices for the Acquisition of Data from Novel Digital Devices 

2016-10-08 SWGDE Comments on Forced Minimization Requirements for the Seizure of Digital Evidence 

2016-06-23 SWGDE Best Practices for Vehicle Infotainment and Telematics Systems v2 

2016-02-08 SWGDE Best Practices for Collection of Damaged Mobile Devices v1.1 

2016-02-08 SWGDE Best Practices for Chip-Off 

2015-09-29 SWGDE Mac OS X Tech Notes v1.3 

2015-09-29 SWGDE Best Practices for Examining Mobile Phones Using JTAG 

2014-09-05 SWGDE Focused Collection and Examination of Digital Evidence 

2014-09-05 SWGDE Best Practices for Handling Damaged Hard Drives 

2014-09-05 Digital and Multimedia Evidence as a Forensic Science Discipline v2 

2013-02-11 SWGDE Core Competencies for Mobile Phone Forensics v1 

2013-02-11 SWGDE Best Practices for Mobile Phone Forensics v2 

2012-09-13 SWGDE Model SOP for Computer Forensics v3 

2006-04-12 SWGDE Data Integrity Within Computer Forensics v1