§ Guide library
eDiscovery guide topics
Every guide in the library, grouped by subject. Read each one in full online or download the PDF, free and without registration.
Ref · E-D · 2026 · §GTXClass · ConfidentialJuris · England & WalesStatus · Active
§ Guide library
Search all 161 guides →New guides, sector briefings and disclosure checklists are added to this library as they are published. New here? Read the library FAQ on searching, reading and citing guides, browse guides by topic, or follow library updates for new guides and revisions. To match your own facts to answers and guides, open the case builder.
Mobile and messaging evidence (24)Forensic collection and imaging (21)Electronic disclosure practice (20)Apple and macOS forensics (14)Deleted data and recovery (13)Cloud evidence (10)Chain of custody and defensibility (8)Servers, NAS and virtual environments (8)Custodians and data mapping (7)Expert evidence and reports (7)Metadata and timestamps (7)Open source, web and log evidence (7)
- A Privileged Document Has Been Disclosed What Happens Next
- AI Generated Documents Provenance And Detection
- Android Acquisition Logical File System And Physical
- Android App Data And Third Party Application Forensics
- Android Backups Local Google And Manufacturer Cloud
- Android Deleted Data SQLite And Unallocated Space
- Android Encryption Secure Boot And Lock Screen Protections
- Android Forensics The Fragmented Landscape
- Android Location Fused Location WiFi And Cell Data
- Android Malware Stalkerware And Compromise
- Android Messaging SMS RCS And Messaging Apps
- Android Photos Media And Metadata
- Android Secure Folders Knox And Manufacturer Security Containers
- Android Usage Activity And System Artefacts
- APFS And The Apple File System
- Apple Mail Archives And Email Threading On MacOS
- Apple Watch And Paired Device Forensics
- BitLocker FileVault And Full Disk Encryption
- Browser History And Internet Artefacts
- Building A Digital Timeline For Litigation
- BYOD And Disclosure
- Can File Timestamps Be Trusted
- Can We Collect Only Relevant Data Instead Of Imaging Everything
- Can You Prove A USB Drive Was Connected
- Can You Prove Who Deleted A File
- CCTV Evidence
- CFL Benefits Of Early Case Assessment In EDiscovery
- CFL Digital Forensics Services Brochure
- Citrix VDI And Remote Desktop Where The Evidence Actually Resides
- Citrix VDI And Remote Desktop Where The Evidence Actually Resides (1)
- Citrix VDI And Remote Desktop Where The Evidence Actually Resides (2)
- Cloud Evidence Is Not Just Files
- Collecting Evidence From Google Workspace
- Collecting Evidence From Microsoft Teams Private And Shared Channels
- Collecting Without The Password
- Completing The Disclosure Review Document A Technical And Legal Guide
- Control Of Electronic Documents What Lawyers Need To Investigate
- Cooperating On Electronic Disclosure Without Giving Away Your Case
- Coordinating Forensic Collection Across Multiple Offices And Countries
- CRM Evidence Salesforce HubSpot
- Cryptocurrency And Blockchain Tracing
- Custodian Abroad Cross Border Collection
- Damaged Computers And Data Recovery
- Data Exfiltration To Cloud Storage
- Deduplication Explained
- Deepfakes And Synthetic Media
- Detecting Backdated Or Manipulated Documents
- Digital Chain Of Custody A Practical Guide For Lawyers
- Digital Forensic Evidence What Every Defence Lawyer Needs To Know Computer Forensics Lab
- Digital Forensics In Corporate Fraud Investigations
- Digital Forensics Services
- Digital Redaction That Cannot Be Reversed
- Document Management Systems In Disclosure
- Domain DNS And Hosting Records
- Door Access Swipe Cards And Building Logs
- Early Data Assessment Before Disclosure Costs Escalate
- EDisclosure Or Digital Forensics Choosing The Correct Approach
- Electronic Disclosure Explained A Practical Guide For UK Lawyers
- Email Threading
- ERP Evidence SAP Oracle
- External Storage Devices As Evidence
- File Wiping Anti Forensics And The Evidence They Leave Behind
- FileVault The Secure Enclave And Apple Encryption
- Finding The Evidence A Lawyers Map Of Modern Electronic Data Sources
- Forensic Collection From Corporate File Servers
- Forensic Collection Of Exchange Online Mailboxes
- Forensic Data Collection Explained For Lawyers
- Forensic Evidence From Cloud Infrastructure AWS Azure Google Cloud
- Forensic Evidence From Dropbox Box And ShareFile
- Forensic Image Logical Extraction Or Targeted Collection
- Gatekeeper XProtect And MacOS Malware Artefacts
- Geolocation Evidence
- GitHub GitLab And Source Code As Evidence
- Google Vault In Litigation
- Guide 5 Identifying The Right Custodians In Electronic Disclosure
- How Lawyers Should Instruct A Digital Forensic Expert
- How To Build A Defensible EDisclosure Strategy At The Start Of A Case
- How To Design Defensible Keyword Searches
- How To Draft An Electronic Disclosure Production Protocol
- ICloud The Account As The Real Evidence Store
- Identifying The Right Custodians In Electronic Disclosure
- IMessage SMS And Messaging Apps On IOS
- Initial Disclosure What Should Be Provided And What Should Be Preserved
- Investigating Suspected Employee Data Theft
- IOS App Data And Third Party Application Forensics
- IOS Backups ITunes Finder And ICloud
- IOS Encrypted Apps And Secure Messengers
- IOS Full File System Vs Logical Acquisition
- IOS Health Fitness And Motion Data
- IOS Knowledge And Biome The Device Activity Record
- IOS Location Services Significant And Frequent Locations
- IOS Photos Media And Location Metadata
- IOS Spyware Stalkerware And Mobile Compromise
- IPhone And IPad Forensics The Acquisition Challenge
- IPhone Forensics The Defensible Mobile Evidence Bundle
- Known Adverse Documents In The Digital Age
- Legal Professional Privilege In Large Electronic Datasets
- Locked Mobile Devices
- Mac Evidence In Litigation
- MacOS And Apple Silicon Forensics
- MacOS Enterprise Management And MDM Artefacts
- MacOS Mail Messages And Notes Forensics
- MacOS Spotlight And Metadata Deep Dive
- MacOS System Artefacts
- Metadata For Lawyers What It Can And Cannot Prove
- Microsoft Purview Or Independent Forensic Collection
- Mobile Phone Forensics
- NAS Evidence RAID Snapshots Shared Access Logs And Deleted Data
- Native Documents PDFs Or Images Which Production Format
- OCR When Searchable Does Not Mean Accurate
- OneDrive Evidence
- OSINT Open Source Intelligence In Litigation
- PD57AD Explained For Litigation Lawyers
- Personal Email Accounts In Disclosure
- Planning An On Site Digital Evidence Collection
- Preparing A Forensic Collection Protocol
- Preserving Evidence After A Cyber Attack Or Ransomware Incident
- Preserving Social Media Evidence
- Proportionality In EDisclosure When Is Enough Enough
- Proving Who Created Or Edited A Document
- RAID NAS And Server Recovery
- Recovering Deleted CCTV And DVR Footage
- Recovering Evidence From Deleted Microsoft 365 User Accounts
- Recovering Historical Documents From Snapshots And Volume Shadow Copies
- Recovering Previous Versions Of Cloud Documents
- Remote Employee Collection
- Remote Forensic Collection When Can It Be Defensible
- SaaS Platforms As Undiscovered Repositories
- Safari And Browser Artefacts On MacOS
- Shared Mailboxes Delegated Access And Who Really Sent The Email
- SharePoint As A Disclosure Source
- Should A Computer Be Imaged While Running Or Switched Off
- Should Backup Systems Be Searched For Disclosure
- Signal And Ephemeral Messaging
- Slack EDiscovery
- SMS And IMessage Evidence
- Technical Preparation For A Disclosure Case Management Conference
- Technology Assisted Review For UK Lawyers
- The Defensible Multi Source Evidence Bundle
- The Electronic Discovery Reference Model For UK Litigation Teams
- The First EDisclosure Meeting 50 Questions Lawyers Should Ask
- The Google Account Androids Cloud Estate
- The Missing Evidence Problem
- Time Machine And MacOS Backup Analysis
- UK Digital Forensics for US Litigation Teams
- UK Digital Forensics Support For US Litigation Teams
- Understanding And Controlling EDisclosure Costs
- Using Generative AI Responsibly In Electronic Disclosure
- Vehicle Infotainment And Telematics Forensics
- Virtual Machines As Evidence
- Wear OS And Android Paired Device Forensics
- Wearables And Fitness Tracker Forensics
- Website Web Server And Application Logs
- What Evidence Can Be Recovered From A Windows Computer
- What Evidence Can Be Recovered From A Windows Computer (1)
- What Happens During EDiscovery Processing
- What Is A Forensic Hash And Why Does It Matter
- What Is A Reasonable Electronic Search
- WhatsApp Evidence
- Who Accessed Or Downloaded A Confidential Document
- Why Lawyers Should Test Search Terms Before Agreeing Them
Instruct the practice
Bring us in early.
Defensibility is built, not retrofitted.
Whether you are responding to a regulator, preparing for disclosure, or scoping an internal investigation, start the chain of custody with a short, confidential conversation.
