§ Guide, full text

External Storage Devices As Evidence

External storage devices are crucial evidence sources in UK litigation, revealing copied files, timestamps, and deleted data. This guide details their examination, from intake and imaging to attribution and common pitfalls. It assists practitioners in understanding what these devices disclose and how to interpret their contents.

18 pages · 22 min read

Loading the PDF reader

External Storage Devices As Evidence

EXTERNALSTORAGEEVIDENCE · A GUIDE FOR UK LAWYERS External Storage Devices as Evidence What Memory Sticks, External Drives and Cards Reveal: Copied Files, Timestamps, Deleted Data and Attribution COMPUTER FORENSICS LAB

§ ABOUT THE AUTHOR PREPARED BY COMPUTER FORENSICS LAB E-DISCOVERY TEAM

§ CONTENTS In this guide 01 Executive summary 02 The problem in plain English: the object in the evidence bag 03 Getting the device examined: intake, imaging, integrity 04 What the live file system tells you 05 Timestamps on external media: reading the copy story 06 Deleted data: recycle folders, unallocated space and the SSD problem 07 Whose device, whose hand: attribution on p or table media 08 Source architecture: where else the evidence lives 09 Worked examples 10 Common mistakes and technical limitations 11 Questions to ask · Suggested wording 12 Checklist and red flags · When to involve a digital forensic expert 13 Frequently asked questions 14 Glossary · References · Disclaimer · How a specialist laboratory can assist

§ 01 · ORIENTATION Executive summary THE HEADLINE POINT: THEDEVICEISDIRECTEVIDENCE; TREATITLIKETHEEXHIBITIT

§ 02 · FIRST PRINCIPLES The problem in plain English: the object in the evidence bag

§ 03 · INTAKE Getting the device examined: intake, imaging, integrity

§ 04 · WHAT IS THERE What the live file system tells you

§ 05 · WHENITGOTTHERE Timestamps on external media: reading the copy story

§ 06 · WHAT WAS THERE Deleted data: recycle folders, unallocated space and the SSD problem

§ 07 · WHOSE H AND Whose device, whose hand: attribution on p or table media

§ 08 · THEWIDERMAP Source architecture: where else the evidence lives EVIDENCE THE DEVICE SERVER S / SOURCE CORPORATE ONWARD DELETED / MACHINE(S) TOOLING DEVICES RECOVERABLE SOURCE CLOUD

§ 09 · IN THE WILD Worked examples EXAMPLE1 · THETWO - CLOCKSIGNATUREANDTHEINJUNCTIONDATE EXAMPLE2 · THESNAPPEDSTICK, RECOVERED EXAMPLE3 · THEDRIVETHATCLEAREDHER

§ 10 · WHEREITGOESWRONG Common mistakes and technical limitations Common mistakes Technical limitations

§ 11 · INTERROGATORIES & DRAFTING AIDS Questions to ask · Suggested wording Ask your client Ask your opponent Ask your e Discovery / forensic provider SUGGESTED WORDING · INSTRUCTION FOR DEVICE EXAM IN AT I ON

§ 12 · QUICK CONTROL Checklist and red flags · When to involve a digital forensic expert The external media checklist Red flags When to involve a digital forensic expert

§ 13 · COMMON QUESTIONS Frequently asked questions We have the stick. Do we still need the computers? The files were deleted from the stick before it was handed over. Gone? Can you tell which computer the files came from? The device belongs to the company but lived on a shared desk. Is attribution hopeless? What about memory cards from cameras, dashcams and phones? Our opponent simply has not produced the drive we know exists. What now?

§ 14 · REFERENCE Glossary Sources and authoritative references DISCLAIMER

§ HOW A SPECIALIST LABORATORY CAN ASSIST Working with Computer Forensics Lab Speak to a forensic examiner, not a salesperson. INSTRUCTTHELAB NEWENQUIRIESEMAILE - DISCOVERY

Cite as: Joseph Naghdi, External Storage Devices As Evidence, Computer Forensics Lab, https://e-discovery.uk/library/external-storage-devices-as-evidence/pdf.

Instruct the practice

Bring us in early. Defensibility is built, not retrofitted.

Whether you are responding to a regulator, preparing for disclosure, or scoping an internal investigation, start the chain of custody with a short, confidential conversation.

WhatsApp