Skip to main content

SWGDE

published documents

Best Practices for Computer Forensic Examinations

18-F-001-2.0

Disclaimer Regarding Use of SWGDE Documents

As a condition to the use of this document and the information contained therein, the SWGDE requests notification by e-mail before or contemporaneous to the introduction of this document, or any portion thereof, as a marked exhibit offered for or moved into evidence in any judicial, administrative, legislative or adjudicatory hearing or other proceeding (including discovery proceedings) in the United States or any Foreign country. Such notification shall include: 1) The formal name of the proceeding, including docket number or similar identifier; 2) the name and location of the body conducting the hearing or proceeding; 3) subsequent to the use of this document in a formal proceeding please notify SWGDE as to its use and outcome; 4) the name, mailing address (if available) and contact information of the party offering or moving thedocument into evidence. Notifications should be sent to secretary@swgde.org.

It is the reader’s responsibility to ensure they have the most current version of this document. It is recommended that previous versions be archived.

Redistribution Policy:

SWGDE grants permission for redistribution and use of all publicly posted documents created by SWGDE, provided that the following conditions are met:

  1. Redistribution of documents or parts of documents must retain this SWGDE cover page containing the Disclaimer Regarding Use.
  2. Neither the name of SWGDE nor the names of contributors may be used to endorse or promote products derived from its documents.
  3. Any reference or quote from a SWGDE document must include the version number (or creation date) of the document and also indicate if the document is in a draft

Requests for Modification:

SWGDE encourages stakeholder participation in the preparation of documents. Suggestions for modifications are welcome and must be submitted via the SWGDE Request for Modification Form or forwarded to the Secretary in writing at secretary@swgde.org. The following information is required as a part of any suggested modification:

  1. Submitter’s name
  2. Affiliation (agency/organization)
  3. Address
  4. Telephone number and email address
  5. SWGDE Document title and version number
  6. Change from (note document section number)
  7. Change to (provide suggested text where appropriate; comments not including suggested text will not be considered)
  8. Basis for suggested modification

Intellectual Property:

All images, tables, and figures in SWGDE documents are developed and owned by SWGDE, unless otherwise credited.

Unauthorized use of the SWGDE logo or document content, including images, tables, and figures, without written permission from SWGDE is a violation of our intellectual property rights.

Individuals may not misstate and/or over represent duties and responsibilities of SWGDE work. This includes claiming oneself as a contributing member without actively participating in SWGDE meetings; claiming oneself as an officer of SWGDE without serving as such; claiming sole authorship of a document; use the SWGDE logo on any material and/or curriculum vitae.

Any mention of specific products within SWGDE documents is for informational purposes only; it does not imply a recommendation or endorsement by SWGDE.

Table of Contents

1. Purpose

The purpose of this document is to describe the best practices for the forensic examination of digital evidence from computers and associated storage media following a forensic acquisition. These processes are designed to maintain the integrity of digital evidence. This document is limited to computers and other storage media (i.e., hard disk drives, flash media, etc.).

2. Scope

This document provides information on the examination and analysis of digital evidence from computers and storage media that have been forensically acquired. The intended audience is personnel qualified to perform examinations on digital evidence acquired from computers and associated storage media. For guidance on recommended training and qualifications, see SWGDE 10-Q-002-3.0 Guidelines & Recommendations for Training in Digital & Multimedia Evidence. For the purposes of this document, the term “examiner” refers to those who perform examinations and analyses of digital evidence acquired from computers and associated storage media.

Examination of mobile devices is beyond the scope of this document and is being covered in the SWGDE publication, SWGDE 18-F-003-1.2 Best Practices for Mobile Device Evidence Collection & Preservation Handling and Acquisition.

3. Limitations

This document is not intended to be a training manual, a step-by-step guide, a replacement of organizational policy or standard operating procedures, nor should it be construed as legal advice. This document is not all inclusive and does not contain information relative to specific commercial products. This document may not be applicable in all circumstances. When warranted, an examiner may deviate from these best practices and still obtain reliable, defensible results. If examiners encounter situations warranting deviation from best practices or organizational policy, they should thoroughly document the specifics of the situation, actions taken, and results of the deviation.

This document is part of a set of best practice guides: SWGDE 18-F-002-1.0 Best Practices for Digital Evidence Collection, SWGDE 17-F-002-1.0 Best Practices for Computer Forensic Acquisitions, SWGDE 18-F-001-1.0 Best Practices for Computer Forensic Examination, and SWGDE 18-Q-002-1.0 Requirements for Report Writing in Digital and Multimedia Forensics.

4. Preparation

Examiners should review documentation provided by the requestor to determine the following:

  • Legal Authority: Confirm proper legal authority has been given to perform examination and analysis. Authority may be granular and restrict what examinations may be performed. For example, specifying permitted dates, artifact types, and search terms. Other legal authorities should be considered (e.g., owner consent, data privacy restrictions, management, or organizational policies). See SWGDE 16-F-002-2.0 Considerations for Required Minimization of Digital Evidence Seizure. The analyst should comply with legal standards and ethical guidelines, respecting privacy rights, and avoiding unauthorized access to and distribution of sensitive information.
  • Scope: Identify the scope of the examination, such as date ranges and artifact types, as well as known restrictions, deviations, or limitations of the These should be communicated with the requestor.
  • Objective: Identify the objective of the examination so the examiner can confirm access to the necessary equipment, software, and processes required to complete the

Prior to beginning an examination, appropriate preparations should be made, as described in the following sections.

4.1 Environment

The examination environment should have adequate power, space, privacy, and cooling necessary that will not impact or disturb the examination and/or analysis process. Consult the National Institute for Standards and Technology’s (NIST) “Forensic Science Laboratories: Handbook for Facility Planning, Design, Construction, and Relocation” for design recommendations. Implement controls and access logs for evidence and ensure chain of custody is maintained throughout the examination lifecycle.

For on-site examinations (i.e., triage), examiners should make best efforts to ensure the device is in a controlled environment. This includes preventing access by non-forensic personnel and limiting external factors that could disrupt the forensic processes. For more information about on-site evidence handling, see SWGDE 17-F-002-1.0 Best Practices for Computer Forensic Acquisitions.

4.2 Examination workstation

Examination workstations should provide an isolated, secure, known environment to perform analysis. The following factors should be considered when configuring an examination workstation.

4.2.1 System Specifications

The workstation should meet or exceed the minimum requirements for the forensic tools employed throughout the examination and the type of evidence being examined. The system should have adequate storage to complete the examination, including storage to support the installation of all forensic tools and cache repositories for processing the volume of evidence being examined.

4.2.2 Software

Forensic tools should be updated, tested, and validated before performing examinations. This may require the workstation to have internet access before or during the forensic examination. If a forensic tool requires network or internet access to validate a license or properly function, examiners should be prepared to address this requirement. Forensic examiners must ensure that the use of forensic tools complies with export restrictions and terms of service, which may limit the geographic locations where the tools can be used. After the examination, consider archiving forensic software logs within case data

4.2.3 Sanitization

Lab procedures should ensure data between cases are not commingled. For investigations involving confidential or sensitive material, the operating system drive of the examination workstation should be sanitized to ensure no residual or cached data remains on the system. For example, the following techniques may be implemented:

  • Virtualization Technology: A virtual machine can be used to encapsulate case data in a working container. A tested, patched, sanitized version of the operating system and forensic tools could be copied and reused for each case.
  • Sanitized Image: A known image of the workstation in a sanitized state can be used to restore the host drive before each examination. This may require patching and maintaining the known image for distribution between examinations.
  • Folder Structures: Use file system and folder organization along with forensic tools to isolate cases.

4.3 Documentation

Examiners should take contemporaneous notes relevant to their examination including, but not limited to, the forensic hardware and software tools used to perform the examination, verification hash values of the evidence examined (e.g., forensic image, forensic extraction, logical dataset) and sources of artifacts of evidentiary interest. Organizational systems should exist to maintain any notes with their case for later review. Organizations may implement a quality assurance process to review documentation and exam processes.

Chain of custody documentation should be created throughout the examination and analysis phases to maintain the integrity and chain of custody of the data, including derivative evidence. This ensures that the evidence remains admissible in legal proceedings.

5. Considerations

Any examination activity should be accompanied by a scope and an objective. Examinations are more likely to produce useful results when they are targeted or guided by dialog with the requestor. Primary consideration for any examination activity should be made to accomplish the parameters of the request. Examiners should keep the requestor advised of any additional information that may impact the specifics of the exam request (i.e., new leads, conflicting information, or exculpatory information).

Conducting a direct examination on the original evidence should be avoided if possible. Original digital evidence should be protected with a software or hardware write blocker. Analysis should be carried out on a copy of the original digital evidence to avoid accidental spoliation or obfuscation. See SWGDE 17-F-002-1.0 Best Practices for Computer Forensic Acquisitions for additional information. The examiner should ensure the forensic image is archived before the examination.

6. Examination

The examination phase is the application of forensic methodologies and tools to access, recover, identify, and extract forensic artifacts. An examination should begin with a review of available information about the acquisition of the evidence such as acquisition methods, documented hardware configuration, system clock, and BIOS/UEFI settings, when the original device is available for examination. A systematic review of the data is then conducted to determine its relevance to an investigation. During the examination, the following items should be considered where relevant to the request:

6.1 System Specifications

  • Disk Geometry: The examiner should review the configuration of the storage media to determine its partitioning scheme and account for all storage areas on the device.
  • File Systems: Identify the file system format and partition scheme, or lack thereof. This could reveal physical disk encryption, proprietary file systems, hidden volumes, dual boot systems, and necessary information to structure the investigation moving forward.
  • Operating Systems: Identify the file system format and partition scheme, or lack This could reveal physical disk encryption, proprietary file systems, hidden volumes, dual boot systems, and necessary information to structure the investigation moving forward.
  • Encryption: Consider identifying encrypted files, such as calculating entropy and searching for known headers, to identify datasets that would be excluded from forensic searches without decryption.
  • Embedded/Mislabeled Files: Consider verifying file signatures and expanding compound files (e.g., ZIP files) for mislabeled or embedded data that could be inadvertently excluded from the examination.

6.2 System Data

  • System Information: The Windows registry, macOS property list files, and Linux logs contain a wealth of information about the system settings, historical events, and user
  • Memory: Random Access Memory (RAM), which can only be acquired during the collection of the device, and page files (swap files) contain additional volatile user and system data that have not been written to the disk.
  • Mounted Devices: Artifacts that identify devices mounted to the system, including physical external devices and mapped network drives.
  • Deleted Data: Consider recovering deleted file formats that fall within the scope and objective of the examination from file slack, partition slack, disk slack, and unallocated space, when applicable.
  • Time Zone: Although most modern operating systems have time zone synchronization from the internet, the time zone settings should be confirmed.

6.3 Application Data

  • Anti-forensic Tools: The presence of anti-forensic tools that can affect the completeness or integrity of the data, such as permanent deletion tools, obfuscation tools (e.g., steganography, encryption), or hex editors should be identified.
  • Antivirus and Security Applications: These tools can generate logs identifying threats present on the device, files that previously existed on the device, or log file movement to external locations.
  • Chat Applications: Native and third-party chat applications can contain communications that may not otherwise be available through mobile device forensics or from the service
  • Email Applications: Mailboxes (e.g., EDB, .EML, .MBOX, .MSG, .OST, .PST) can contain copies of email communication and attachments from online email accounts.
  • Hypervisors: The existence of hypervisors may reveal additional sources of evidence, such as Hyper-V, VMWare, Parallels, and VirtualBox.
  • Internet Browsers: Browser files (e.g., databases) and cache directories can contain artifacts representing the user’s web browsing history and contents of webpages.
  • Monitoring or Productivity Applications: The presence of applications that can monitor employee activity or parental monitoring applications can lead to additional evidence sources of user activity.
  • Peer-to-Peer (P2P) Applications: The presence of traditional peer-to-peer and BitTorrent clients can identify files downloaded, user searches, and network
  • Social Media Applications: Desktop and mobile versions of social media applications can be found on a computer that can contain user account information, communications, and media that may not otherwise be available through mobile device forensics or the Electronic Service Provider.
  • Third-Party Applications: The installation of applications beyond the native software that come preinstalled with the operating system can reveal the user’s sophistication level and primary use of the device (e.g., work, school, personal).

6.4 User Data

  • Profiles: Identifying individual user accounts, unique account identifiers (e.g., Windows Security Identifier), file permissions, settings, and user-specific applications.
  • Indicia of Ownership: Locating personal data and activity for specific individuals can be used to demonstrate ownership or control of a device.

7. Data Analysis

The analysis phase is the assessment and interpretation of the data extracted during the examination phase and its application on the facts of the investigation. The data discovered or recovered from the examination is interpreted for probative value and conclusions may be drawn from it. The methods employed and findings of the analysis should be sound, supported by the data, replicable, and defensible. Any conclusion derived from the data analysis should be written in a report that is concise and complete. Guidance on report writing is being addressed in the SWGDE publication, SWGDE 18-Q-002-1.0 Requirements for Report Writing in Digital and Multimedia Forensics.

The analysis is dependent upon the following factors:

  • Nature of Investigation: Investigations involving protected or confidential data, and data involving minors and victims, may require additional security measures.
  • Scope and Purpose of Investigation: The artifacts identified during the examination phase may need to be further limited in the analyst phase, such as timeframe or data
  • Complexity of Evidence: Factors that may complicate an analysis and should be documented include, but are not limited to, encryption, the application of anti-forensic tools, the sophistication of the device user, and proprietary systems or servers.
  • Manual Analysis: Automated tools that parse device data may not always fully interpret or process all relevant user data. An analyst should consider the limitations of the examination tools and manually analyze data that may have been excluded by a If an application of value was parsed, further analysis may be required to extract additional metadata not initially reported by a tool, such as data embedded within databases and configuration files. Some forensic tools provide scripting interfaces to allow examiners to extend the automated processing of artifacts.
  • Expertise of the Analyst: Considerations should be made regarding an individual analyst’s experience and knowledge on the unique factors of the evidence involved.

8. Additional Resources

  • Aguilar, James, et “Forensic Science Laboratories: Handbook for Forensic Planning, Design, Construction, and Relocation.” NIST Interagency/Internal Report (NISTIR) – 7941. NIST, 2013, https://nvlpubs.nist.gov/nistpubs/ir/2013/NIST.IR.7941.pdf.
  • International Organization for Standardization. Information Technology — Security Techniques — Guidelines for Identifications, Collection, Acquisition, and Preservation of Digital Evidence. ISO/IEC 27037:2012. ISO, 2012, https://www.iso.org/standard/44381.html.
  • Scientific Working Group on Digital Evidence. Best Practices for Computer Forensic Acquisitions. SWGDE 17-F-002-2.0. SWGDE, 2017, https://www.swgde.org/17-f-002/.
  • Scientific Working Group on Digital Evidence. Best Practices for Computer Forensic Examination. SWGDE 18-F-001-1.0. SWGDE, 2018, https://www.swgde.org/18-f-001/.
  • Scientific Working Group on Digital Evidence. Best Practices for Digital Evidence Collection. SWGDE 18-F-002-1.0. SWGDE, 2018, https://www.swgde.org/18-f-002/.
  • Scientific Working Group on Digital Evidence. Best Practices for Mobile Device Evidence Collection & Preservation, Handling, and Acquisition. SWGDE 18-F-003-1.2. SWGDE, 2018, https://www.swgde.org/18-f-003/.
  • Scientific Working Group on Digital Evidence. Considerations for Required Minimization of Digital Evidence Seizure. SWGDE 16-F-002-2.1. SWGDE, 2016, https://www.swgde.org/16-f-002/.
  • Scientific Working Group on Digital Focused Collection and Examination of Digital Evidence. SWGDE 14-F-003-1.0. SWGDE, 2014, https://www.swgde.org/14-f- 003/.
  • Scientific Working Group on Digital Evidence. Guidelines & Recommendations for Training in Digital & Multimedia Evidence. SWGDE 10-Q-002-3.0. SWGDE, 2010, https://www.swgde.org/10-q-002/.
  • Scientific Working Group on Digital Requirements for Report Writing in Digital and Multimedia Forensics. SWGDE 18-Q-002-1.0. SWGDE, 2018, https://www.swgde.org/18-q-002/.

9. History

Revision Issue Date Section History
1.0 DRAFT
1/11/2018
All
Initial draft created and SWGDE voted to release as a Draft for Public Comment.
1.0 DRAFT
4/17/2018
All
Formatted and technical edit performed for release as a Draft for Public Comment.
1.0 DRAFT
6/14/2018
No changes. SWGDE voted to publish as an Approved document.
1.0
7/11/2018
Formatted and published as Final Approved Document.
2.0 DRAFT
1/9/2024
Five-year review draft created.
2.0 DRAFT
1/15/2025
SWGDE voted to release as Draft for Public Comment.
2.0 DRAFT
2/10/2025
Formatted for release as Draft for Public Comment.
2.0
6/27/2025
SWGDE voted to release as Final Approved Document.
2.0
7/28/2025
Formatted for release as Final Approved Document.

Version: 2.0 (7/28/2025)