§ PDF library

Ask The Library

Ask a question about disclosure, digital forensics or evidence handling and get an answer drawn from the text of our published UK guides, with citations you can open at the exact passage.

Ref · E-D · 2026 · §ASKClass · ConfidentialJuris · England & WalesStatus · Active

Ask the library

Ask a question in plain English. The assistant reads the full text of every guide and Knowledge Centre article, answers from what it finds and points you to the most relevant PDF.

Answers come from published material only and are general information, not legal advice. Conversations are saved in this browser.

Answers are drawn only from the wording of our published guides and Knowledge Centre articles, with a citation you can open at the exact passage. This is general information about our published material, not legal advice. Browse the full library or read the library FAQ.

Answers written from the guides

These are the questions visitors ask most often, each one answered in full from the wording of the published guides rather than a single FAQ line, with the guide in the Knowledge Centre that covers the subject in depth.

Can we start with ordinary collection and go forensic later if something emerges?

You can only partially start with an ordinary collection and upgrade to a forensic approach later.

Guide in the Knowledge Centre: EDisclosure Or Digital Forensics Choosing The Correct Approach

Sources: EDisclosure Or Digital Forensics Choosing The Correct Approach, Forensic Data Collection Explained For Lawyers, Can We Collect Only Relevant Data Instead Of Imaging Everything, Preparing A Forensic Collection Protocol

Put this to the assistant

When does a disclosure matter actually require forensic exam in at i on?

A disclosure matter requires forensic examination when an issue turns on authenticity, deletion, alteration, backdating, attribution, exfiltration or device usage, or when a source is…

Guide in the Knowledge Centre: EDisclosure Or Digital Forensics Choosing The Correct Approach

Sources: EDisclosure Or Digital Forensics Choosing The Correct Approach, Initial Disclosure What Should Be Provided And What Should Be Preserved

Put this to the assistant

What if the foreign subsidiary refuses, or local law blocks transfer?

If a foreign subsidiary refuses to provide documents or local law blocks their transfer, you must take all permissible steps to obtain them and provide the English court with evidence of any genuine…

Guide in the Knowledge Centre: Control Of Electronic Documents What Lawyers Need To Investigate

Sources: Control Of Electronic Documents What Lawyers Need To Investigate, Custodian Abroad Cross Border Collection

Put this to the assistant

Do costs arguments really move courts?

Measured costs arguments do indeed move courts, as the e-disclosure regime is built around proportionate cost and judicial budget management.

Guide in the Knowledge Centre: Understanding And Controlling EDisclosure Costs

Sources: Understanding And Controlling EDisclosure Costs, Early Data Assessment Before Disclosure Costs Escalate, Proportionality In EDisclosure When Is Enough Enough, Electronic Disclosure Explained A Practical Guide For UK Lawyers

Put this to the assistant

Are e Disclosure costs recoverable from the losing party?

E-disclosure costs are generally recoverable from the losing party as costs of the proceedings, provided they meet the usual tests of being reasonably incurred, reasonable in amount and proportionate.

Guide in the Knowledge Centre: Understanding And Controlling EDisclosure Costs

Sources: Understanding And Controlling EDisclosure Costs, Electronic Disclosure Explained A Practical Guide For UK Lawyers, Cooperating On Electronic Disclosure Without Giving Away Your Case

Put this to the assistant

Do we need to tell staff what is happening?

Whether you need to tell staff what is happening is a lawyer's decision made during the planning stage, balancing transparency with the risk of tipping off suspects.

Guide in the Knowledge Centre: Planning An On Site Digital Evidence Collection

Sources: Planning An On Site Digital Evidence Collection, The First EDisclosure Meeting 50 Questions Lawyers Should Ask, Investigating Suspected Employee Data Theft, Technical Preparation For A Disclosure Case Management Conference

Put this to the assistant

What do we tell the English court if foreign law blocks disclosure?

If foreign law blocks disclosure, you must inform the English court candidly and early, providing evidence of the constraint and demonstrating that you are doing the lawful maximum to comply.

Guide in the Knowledge Centre: Custodian Abroad Cross Border Collection

Sources: Custodian Abroad Cross Border Collection, Control Of Electronic Documents What Lawyers Need To Investigate, Electronic Disclosure Explained A Practical Guide For UK Lawyers

Put this to the assistant

Questions the guides already answer

Every pair below comes from a published guide. Open the guide for the full wording, or put the question to the assistant above.

IOS Spyware Stalkerware And Mobile Compromise

My client thinks their phone is being tracked. Where do we start?
With their safety, before any exam in at i on (
Why can't you just scan the phone and be sure?
Because detection on iOS is genuinely limited (
Should we just remove any monitoring we find?
Not reflexively, because removal can escalate risk (
Ask about this guide

Android App Data And Third Party Application Forensics

How does Android app forensics differ from iPhone app forensics?
The core is the same; the openness adds more (
What is a cloned or dual app?
A second copy of an app running under a different account on the same phone (
Can apps really be hidden on a phone?
Yes, and the open ecosystem makes it easy (
Why verify an app's version and whether it's modified?
Because a modified app behaves differently, and reading it as genuine produces confident nonsense (
Ask about this guide

IOS Encrypted Apps And Secure Messengers

Aren't apps like Signal simply unrecoverable?
No, that misunderstands what the encryption protects (
So can you always recover secure-messenger conversations?
No, and claim in g so would be the opposite error (
Does using a secure messenger look suspicious?
Not in itself, and it is treated neutrally (
Ask about this guide

Android Acquisition Logical File System And Physical

Why does the acquisition method matter so much for the evidence?
Because a shallow extraction cannot see what a deep one holds (
Ask about this guide

Android Backups Local Google And Manufacturer Cloud

How is an Android phone backed up?
Usually in several ways at once, none complete (
Why are backups so valuable?
Because each is a prior state that survives the phone (
How are backups obtained law full y?
By consent, lawful process or production (
Ask about this guide

Gatekeeper XProtect And MacOS Malware Artefacts

Someone says "a virus did it". How do you test that?
Even-handedly, by asking specific questions (
Why the urgency about not shutting the Mac down?
Because compromise evidence is often volatile (
Ask about this guide

Android Deleted Data SQLite And Unallocated Space

Can deleted data be recovered from an Android phone?
Often yes, but it depends on depth, encryption and timing (
Why does the depth of extraction matter so much?
Because each depth reaches different deleted data (
What are file-based encryption and TRIM, and why do they matter?
The two modern limits on classic recovery (
So is deleted data on a modern Android phone unrecoverable?
No, because database remnants largely survive the modern limits (
Ask about this guide

IOS Location Services Significant And Frequent Locations

What is Significant Locations?
An iOS feature that records the places a person regularly visits and when (
Does location prove where a person was?
It proves where a phone was; the inference to a person needs care (
Ask about this guide

Wear OS And Android Paired Device Forensics

Why examine the watch and paired devices as well as the phone?
For attribution, their own data, and redundancy (
Are Android watches the same as an Apple Watch forensic all y?
The value is the same; the variety is greater (
Does the watch prove who was doing something?
It attributes activity to a person more strongly than a phone, but not absolutely (
What do connection records show?
That the phone paired with a device at a time, which is a proximity signal (
Ask about this guide

Android Encryption Secure Boot And Lock Screen Protections

Can a laboratory just crack a locked Android phone?
For a modern, patched device, usually not, and the picture has changed (
So what do we do with a locked phone?
Preserve its state, pursue the credential law full y, and reach the estate meanwhile (
Why does it matter whether the phone was powered off?
Because state decides what is possible, and a reboot can close a window permanently (
How is the credential obtained law full y?
By cooperation, compulsion or other lawful means (
Ask about this guide

Guide 5 Identifying The Right Custodians In Electronic Disclosure

Which individuals involved in the events in issue have you excluded, and why?
Which relevant custodians have left your or g an is at i on? For each: what has happened to their mailbox, files, chat data and devices, and on what dates? What steps have you taken to preserve custodian data - including suspension of deletion policies, JML freezes and device quarantine - and when? Did relevant individuals use personal devices or accounts (including messaging apps) for the matters in issue, and what steps have you taken in respect of that material? Which shared mailboxes, department a l repositories and systems of record will you search in addition to individual custodians? What de-duplication approach will you apply, and will your productions preserve full custodian information for each document? • • • • • • 1. 2. 3. 4. 5. 6. 7. TECHNICAL LIMITATIONS CFL Electronic Evidence Series · Guide 5 Page 23 Ask the forensic / e Disclosure provider For each custodian and source on our register, what collection method do you recommend, and what will it capture and miss?
How will you verify and document that each collection is complete and attributable (hashes, logs, chain of custody)?
Can you run early data assessment on Tier 1 to map communication patterns and test marginal custodians before we commit to full processing?
How does your platform record custodian metadata, and how is cross-custodian de-duplication handled - is an all custodians field maintained and producible?
For leavers: what are the realistic recovery options per source (converted mailboxes, archives, backups, PST exports), and in what order should we try them? For personal devices and accounts: what independent-examiner protocol do you offer, what filter in g is applied, and who sees what at each stage? Where will custodian data be hosted, who can access it, and what happens to it at the end of the matter (retention, return, certified deletion)? 1. 2. 3. 4. 5. 6. 7. QUESTIONS TO ASK CFL Electronic Evidence Series · Guide 5 Page 24 20 Model wording Adapt to the matter; none of this is a substitute for advice on the facts. Wording A · Instruction to the client to convene custodian identification "To enable us to comply with the disclosure obligations that now apply, please arrange for us to speak with: (i) the person best placed to describe your IT systems, retention policies and leaver processes; (ii) the heads of the departments involved in [the events]; and (iii) the individuals listed in the attached schedule. Each conversation will take 30-60 minutes and will cover their role, communications, devices, accounts and document locations. Please do not ask anyone to gather, tidy or delete material in advance; the purpose is to find where documents are, and nothing should change until we have spoken. Please also tell us immediately of any listed individual who has left or is about to leave, so that their accounts and devices can be preserved today." Wording B · Custodian paragraphs for a hold notice "You have been identified as a person who may hold documents relevant to [the dispute]. 'Documents' includes emails, chat and text messages (including Whats App and similar apps, on work or personal devices), documents and their drafts, spreadsheets, notes, calendars, voicemails and recordings, wherever stored - including personal devices and personal accounts if used for work. From now: (1) do not delete, alter or dispose of any such material; (2) switch off any disappearing-message settings in chats relating to [the matter]; (3) do not reset, replace, repair or return any device that may contain such material without first contacting [name]; (4) confirm by reply that you have read and will comply with this notice. If in doubt, keep it and ask." Wording C · Proposing custodians to the opponent "Our client proposes to search the documents of the following custodians, whose roles and date ranges are set out in the enclosed schedule: [list]. These individuals were identified from the statements of case, interviews conducted with [n] members of staff, and analysis of communication patterns in an initial dataset. Our client will additionally search the following non-custodial sources: [shared mailboxes; repositories; systems]. We have preserved, but do not presently propose to search, the documents of [names/roles], for the reasons given in the schedule; our client will keep that position under review and invites your comments. Please provide the equivalent information for your client, including in respect of former employees and any relevant personal devices or accounts." Wording D · Instructing the provider on custodian collections "Please collect, for each custodian listed in Schedule 1, the sources identified against their name, apply in g the date ranges stated. Collections are to be forensic all y sound and documented: for each, record custodian, source, method, tool and version, o per at or, date/time, scope applied and verification hashes, and maintain chain-of-custody records. Custodian attribution must be preserved through processing; apply global de-duplication only if all custodians holding each document remain recorded and reportable. Personal devices and accounts listed in Schedule 2 are to be handled under the independent-examiner protocol at Schedule 3 [scope; filter in g; who sees what; return/deletion of out-of-scope material]. Host all data in [the UK/EEA]; at the conclusion of the matter, retain for [period] and then delete with certification. Report anything suggesting data loss, wiping or tampering immediately and before further processing." MODEL WORDING CFL Electronic Evidence Series · Guide 5 Page 25 21 Custodian identification checklist 22 Red flags TREAT ANY OF THESE AS A STOP-AND-ESCALATE SIGNAL A key actor resigned shortly before or after the dispute arose - and nobody has checked what happened to their account and devices. IT cannot say what the leaver process did to a named individual's mailbox, or the answer changes between askings. A custodian's interview answers conflict with system records (accounts or devices they "never used" show recent activity - or the reverse). Unexplained gaps: an obvious custodian has almost no documents for a critical period, or a thread's replies exist without the originals. A custodian "tidied up", ran a cleaner tool, or factory-reset a phone after the hold notice. Work was conducted in personal channels and the custodian is reluctant to discuss preservation of them. The opponent's custodian list omits the individuals your documents show at the centre of events, or refuses date ranges and reasons. Devices of departed custodians were reissued or recycled after litigation was in contemplation. Delegates or shared accounts sent key documents "as" a principal who denies knowledge. Several of these fall within later guides on deleted evidence and destruction investigations (Guides 27-30). The immediate steps are always the same: preserve what remains, document the state of things as found, and take specialist advice before anyone touches the source again. Issues extracted from statements of case and translated into events, actors, periods and systems☐ Period-specific org charts, project lists and HR joiners/movers/leavers report obtained☐ IT / organisational-knowledge interviews completed (systems, retention, JML, archives)☐ Candidate custodian list assembled; custodian and source register opened☐ Hold notices with privacy notice sent to all candidates; acknowledgements logged and chased☐ Per-custodian IT preservation actions completed (mailbox/OneDrive holds, retention suspensions, device quarantine)☐ Leavers: account status confirmed in writing; deletion timers frozen; archive/backup coverage checked☐ Custodian interviews completed on the standard template; snowball names fed back into the register☐ Personal-source use identified; preservation requests sent; independent-examiner protocol agreed where needed☐ Shared mailboxes, department a l repositories, service accounts and systems of record listed as non-custodial sources☐ Tiers assigned; inclusion/exclusion reasons recorded; sampling/EDA evidence filed for marginal decisions☐ DRD Section 2 populated from the register (custodians, ranges, sources, unavailable data explained)☐ Opponent's custodian list obtained with reasoning; their leavers and personal sources questioned☐ De-duplication approach confirmed to preserve full custodian history☐ Register reviewed at each milestone; holds re-verified before DRD certification and production☐ • • • • • • • • • CHECKLIST CFL Electronic Evidence Series · Guide 5 Page 26 23 When to involve a digital forensic expert Routine custodian collections from live corporate systems are e Disclosure work. Involve a digital forensic specialist when the custodian exercise itself raises questions only forensic methods can answer: Leaver reconstruction. Recovering or reconstructing a departed custodian's data from converted mailboxes, archives, backups, reissued devices or unallocated space - and evidencing what was lost, when and by what process. Personal devices and accounts. Acting as the independent examiner in a Phones 4U-style protocol: defensible extraction, filter in g personal material, and reporting within an agreed scope. Attribution disputes. Establishing who used an account or device at the material time from authentication logs, artefacts and device evidence - including delegate-send and shared-login situations. Suspected spoliation. Any red flag in
Ask about this guide

IPhone And IPad Forensics The Acquisition Challenge

What is the single most important thing at seizure?
Preserve the device's favourable state and isolate it from the network (
Why does the passcode matter so much?
Because it is the central determinant of access (
Can every iPhone be extracted?
No, and a reputable expert will not claim so (
Someone might wipe the phone remotely. What do we do?
Isolate it from the network immediately (
Ask about this guide

IPhone Forensics The Defensible Mobile Evidence Bundle

Why not just rely on the strongest piece of evidence?
Because a single source, however striking, is always open to challenge (
What do you mean by "the weakest link"?
The element of the bundle most vulnerable to challenge (
How is the bundle tested before it is served?
By challenging it as the other side would (
Why does seizure matter so much to the final bundle?
Because the foundation is laid, or lost, in the first moments and cannot be relaid (
Ask about this guide

The Google Account Androids Cloud Estate

Why is the Google account so important in Android matters?
Because it often knows more than the phone (
What is Location History, and how reliable is it?
Google's record of where the user went, now called Timeline (
The account shows no Location History. Does that prove the person didn't travel?
No, it may simply reflect the user's settings (
How is Google account data obtained law full y?
By consent, lawful process or production (
Ask about this guide

MacOS Spotlight And Metadata Deep Dive

Isn't the "created" date just when the document was written?
Not necessarily, this is a classic trap (
Ask about this guide

Time Machine And MacOS Backup Analysis

Can a backup recover system logs that have rotated away?
Yes, that is one of its great strengths (
How reliable is a backup as evidence of timing?
Reliable, when authenticated and properly framed (
Ask about this guide

IOS Photos Media And Location Metadata

Why does it matter which date a photo has?
Because a photo carries several dates that mean different things (
We only have a photo someone sent us. Is that enough?
It is a start, but the device original is far better (
Ask about this guide

IOS Knowledge And Biome The Device Activity Record

What are Knowledge C and Biome?
Internal iOS databases that record device activity (
What can these databases show?
Whether the phone was in use and what was being done, at a fine time resolution (
Why do these need an expert to interpret?
Because they are undocumented and cryptic (
How reliable is this evidence?
Reliable when interpreted by expert is e and corroborated (
Ask about this guide

IOS Full File System Vs Logical Acquisition

Can you always do a full-file-system extraction?
No, its availability depends on the device (
Why does the method used need to be disclosed?
Because it determines what the exam in at i on could reach (
Ask about this guide

IOS Backups ITunes Finder And ICloud

Why would an encrypted backup contain more?
Because of how Apple designs local backups (
Ask about this guide

ICloud The Account As The Real Evidence Store

Why look at iCloud rather than just the phone?
Because for many users the account, not the phone, is the real store (
How is iCloud data obtained law full y?
By consent, lawful process, or production (
What is Advanced Data Protection and why does it matter?
It is Apple's optional end-to-end encryption for much iCloud data (
Isn't collecting a whole iCloud account very intrusive?
It can be, which is why it is scoped and minimised (
Ask about this guide

IMessage SMS And Messaging Apps On IOS

The messages are in an end-to-end-encrypted app. Doesn't that stop recovery?
No, it stops interception, not recovery (
Does a message prove who sent it?
It shows the sending account or number; attributing it to a person takes care (
What about disappearing messages?
They limit what survives, and that is stated honestly (
Ask about this guide

Apple Watch And Paired Device Forensics

Does the Watch prove who was doing something?
It attributes activity to a person more strongly than a phone, but not absolutely (
Is Watch health data reliable evidence?
It is valuable but indicative, and sensitive (
How does the paired estate help corroborate evidence?
By providing the same data from several devices (
Ask about this guide

Apple Mail Archives And Email Threading On MacOS

Why not just rely on the printed email chain?
Because a printout hides the very evidence that matters (
What are email headers, and why do they matter?
They are the hidden technical record in every email (
Ask about this guide

IOS App Data And Third Party Application Forensics

Why isn't there one method for reading all apps?
Because every app stores its data differently (
What kind of evidence do apps hold?
An enormous range, depending on the app (
How do you avoid misreading an unfamiliar app?
By understanding it on its own terms and validating the interpretation (
Does app activity prove the phone's owner did it?
It shows account activity; attributing it to a person takes care (
Ask about this guide

MacOS Enterprise Management And MDM Artefacts

Why does it matter whether a Mac is managed?
Because it changes everything about evidence and access (
What does the MDM console actually hold?
A central, independent record of the device (
The device was remotely wiped. Is everything gone?
The local data may be, but the record often is not (
How does a managed Mac connect to the wider case?
Through the enterprise estate it belongs to (
Ask about this guide

Android Secure Folders Knox And Manufacturer Security Containers

What is a Secure Folder or security container?
A second, separately locked space inside an Android phone (
If the phone is unlocked, isn't everything accessible?
No, and that assumption is the commonest mistake (
Can the container be broken into?
Not safely, and it should not be attempted (
Does having a container prove someone was hiding something?
Not by itself, and containers are read in context (
Ask about this guide

IOS Health Fitness And Motion Data

What does "indicative not clinical" mean?
That the data is a sensor estimate, not a medical measurement (
Why is health data treated differently under data protection?
Because it is special-category personal data (
Can it show whether someone was really injured or inactive?
It can test such an account, read honestly (
Does the data prove the phone's owner did the activity?
It shows a device's activity; attributing it to a person takes care (
Ask about this guide

Android Malware Stalkerware And Compromise

Is Android more vulnerable to stalkerware than iPhone?
Its threat surface is larger, and its visibility is greater (
My client thinks their phone is being tracked. Where do we start?
With their safety, before any exam in at i on (
Does an app with broad permissions prove it is spyware?
No, permissions are necessary but not sufficient (
Should we just uninstall any stalkerware we find?
Not reflexively, because removal can escalate risk (
Ask about this guide

Android Location Fused Location WiFi And Cell Data

A location record shows an exact coordinate. Isn't that precise?
Not necessarily, and this is the commonest error (
Google Location History is empty. Does that prove the person didn't travel?
No, it usually reflects the user's settings (
How do you make an Android location finding reliable?
By establishing each fix's source and accuracy, then converging (
Does location prove where a person was?
It proves where a phone was; the inference to a person needs care (
Ask about this guide

Android Usage Activity And System Artefacts

What can these artefacts show?
Whether the phone was in use and what was being done, at fine resolution (
Are these records the same on every Android phone?
No, and that is the key Android caution (
How reliable is this evidence?
Reliable when interpreted by expert is e for the specific device and corroborated (
Ask about this guide

MacOS Mail Messages And Notes Forensics

Why look at Notes?
Because it is often where the most telling content sits (Example 3,
Does a message prove who sent it?
It shows the sending account; attributing it to a person takes care (
Ask about this guide

Safari And Browser Artefacts On MacOS

If a website is in the history, does that mean they chose to visit it?
Not necessarily, this is the central discipline (
What about private or incognito browsing?
It leaves far fewer artefacts, and that limit is stated honestly (
Can browsing prove who was at the keyboard?
It shows a profile's activity; attributing it to a person takes care (
Ask about this guide

Android Photos Media And Metadata

How is an Android photo different from an iPhone photo, forensic all y?
The picture records the same things; it lives in more places (
What is the media store?
Android's index of every media file on the device (
Which date on a photo is the real one?
It depends what is being asked, because there are several (
We only have a photo someone sent us. Is that enough?
It is a start, but the device original is far better (
Ask about this guide

Android Messaging SMS RCS And Messaging Apps

Where are the text messages on an Android phone?
In which ever messaging app is the default, which must be identified first (
What is RCS, and does it change anything?
RCS is the richer modern successor to SMS, and it changes a good deal (
Someone deleted their messages. Can they be recovered?
Frequently yes, from several directions (
The messages were end-to-end encrypted. Doesn't that stop recovery?
No, it stops interception, not end point recovery (
Ask about this guide

Android Forensics The Fragmented Landscape

Why is Android so different from iPhone forensic all y?
Because it is a landscape, not a platform (
What can be recovered from an Android phone?
There is no general answer, only an answer for the specific device (
Is anything the same across all Android phones?
Yes, a common core beneath the variation (
Ask about this guide

MacOS And Apple Silicon Forensics

Can you just image the Mac's hard drive like any other computer?
Not on Apple Silicon (§4). The storage is soldered to the board, so there is nothing to remove; it is hard w are- encrypted, so it is unreadable at rest without the machine and its keys; and secure boot blocks the old trick of imaging it from external media. The classic pull-and-image method simply does not work. The Mac is instead acquired live and logically, on the running, unlocked machine, which is where its data is readable (§5).
What is the single most important thing when seizing a Mac?
Keep it powered on and unlocked (§7, Example 1). A running, unlocked Apple Silicon Mac can be acquired; a switched-off, locked one may be an encrypted brick without the credentials. The reflex from old training, to power a machine down, is exactly wrong here. So the machine is kept awake and unlocked, prevented from locking or sleeping into a locked state, protected from remote wipe, and acquired as soon as possible while access lasts.
Is a live logical acquisition as good as a full image?
For a modern Mac it is the correct and defensible method, not a compromise (§5, Example 2). Because no physical image is obtainable, the live logical or targeted collection, taken from the unlocked machine, hashed, documented and validated, is the sound approach, and done properly it is as accountable and reproducible as a classic image. The rigour, integrity, documentation, validation, is unchanged; only the technique adapts to a machine whose data is readable only while it runs.
The Mac is locked and we do not have the password. Can you break in?
Honestly, usually not by direct attack on a powered-off Apple Silicon machine (§6, Example 3). The credible answer is not a promise to crack it but the lawful alternatives: obtain the password by cooperation or an order (guide 117), and reach the same data through the iCloud account and any backups, which often hold much of it (§8). A reputable expert states this limit plainly rather than overpromising, and pursues the routes that actually work.
Ask about this guide

Data Exfiltration To Cloud Storage

The data went to a personal cloud account. Can we even prove it?
Yes, and usually well: the corporate machine's sync database or browser artefacts name the files and the account (§4), the platform audit log records the downloads or shares (§5), the network bounds the volume, and the destination account: reached through process: holds the material itself (§6). Example 1 was proven at both ends to the minute. The cloud feels elusive and is in fact doubly-recorded.
The employee just shared a folder rather than downloading anything. Is that exfiltration?
Squarely: sharing corporate content to a personal or external address, or creating a link and taking it away, moves the data to the employee's control without a d own load or a USB trace (§3, Example 2): and it is logged as a sharing event with the destination in the platform audit trail, which is why that log is exported first when downloads and USBs come up empty.
Can we get into the employee's personal cloud account?
Through process, not self-help: a preservation letter and undertakings first, then delivery-up and imaging orders, commonly via an independent examiner who reports only on your material and protects the employee's private data (§6, guide 97 §7): the account holds both the manifest and the files. Where the holder will not cooperate, the provider's records are reached by disclosure. Plan the route early; the account can be emptied in minutes.
The employee had a sanctioned personal cloud for home-working. Does that defeat the claim?
Only for what it sanctioned: the innocent-explanation pass (§7, Example 3) separates policy-permitted sync of the employee's working folder from unsanctioned transfers outside it, and the genuine exfiltration usually stands out clearly against the baseline. Running the pass first protects both sides: it narrows an over-broad claim to what will survive, and clears what was legitimate.
Ask about this guide

APFS And The Apple File System

If a file was deleted from an Apple device, is it recoverable?
Often, and more reliably than on older systems (§4, §5, Example 1). APFS uses copy-on-write, so changes write new data and leave old data recoverable, and it takes snapshots, point-in-time pictures of the whole file system, that frequently hold deleted files and earlier versions intact. A document gone from the live file system is very often recovered whole from a snapshot that predates its deletion, or from remnants in free space, provided the device is preserved before the data is overwritten or the snapshots pruned.
What is an APFS snapshot, and why does it matter?
A snapshot is a frozen picture of the entire file system at a moment in time (§4). The operating system and Time Machine create them automatically, so a device usually holds several without the user knowing. They matter because they can preserve files as they were at a past moment, including material since deleted or altered, making them the richest source of prior states on an Apple device and a powerful way to prove what existed on the device, and when.
Can we prove a document was altered after it was signed?
Frequently, using APFS (§5, §7, Example 2). Because APFS retains earlier data, a prior version of the document can often be recovered from a snapshot or copy-on-write remnants, and compared with the version relied on. If the comparison shows a change made after the purported date, that exposes the alteration or backdating (guide 109). The interpretation is done carefully, reading timestamps and clone relationships correctly, so the comparison rests on a sound understanding of each recovered version.
Why does it matter whether something is a clone?
Because a clone is not an independent copy (§3, §6, Example 3). APFS clones share the same underlying data until one is changed, so two apparent copies may really be one object with two names, not two separate duplicates that were made and moved. Mistaking a clone for independent duplication overstates the facts. Establishing the clone relationship before drawing conclusions about copying or distribution is essential to an accurate account, which is why interpretation matters as much as recovery.
Ask about this guide

Forensic Evidence From Dropbox Box And ShareFile

Do Dropbox, Box and Share File keep the kind of logs we need?
Business and enterprise tiers do: activity logs of views, downloads, edits, shares and deletions with user and timestamp, plus version histories and sharing records (§3): personal and small-business tiers log less and retain shorter, and export capability varies by product. The account's actual tier and retention are established first, and the desktop client corroborates what ever the platform kept.
The account has been deleted. Is the evidence gone?
Not necessarily: the desktop-client database on every machine that synced it survives the account, naming the files and the account (§4, Example 2 in reverse); the platform provider's server-side records are reachable by process; and collaborators hold their side of every share. The two-record method exists precisely so that a deleted account is not a dead end.
Someone shared a folder externally. How do we find out who reached it?
From the sharing and activity logs: the link's creation names the creator and time, and: where the platform logs link usage: the access record names who followed it and from where (§5, Example 1's lingering collaborator). Where the platform logs only that a link exists, the "who reached it" question is answered as far as it allows, and the collaborators' own records fill the gap.
We found a Dropbox client on a laptop but nobody admits to the account. What now?
The local database names the account and lists what it held (§4, Example 2); the network and expense records confirm its use and who paid; and the account is then reached through the party's cooperation once its existence is undeniable, or through process if it is personal. Shadow IT hides in exactly this way, and the end point is where it surfaces.
Ask about this guide
Instruct the practice

Bring us in early. Defensibility is built, not retrofitted.

Whether you are responding to a regulator, preparing for disclosure, or scoping an internal investigation, start the chain of custody with a short, confidential conversation.

WhatsApp