FILE SERVER EVIDENCE · A GUIDE FOR UK LAWYERS
Forensic Collection from Corporate
File Servers
Shared Drives, Permissions, Snapshots, Deleted Files and the Attribution
Problem
COMPUTER FORENSICS LAB
§ ABOUT THE AUTHOR
PREPARED BY COMPUTER FORENSICS LAB E-DISCOVERY TEAM
ACPO / NPCC DIGITAL EVIDENCE PRINCIPLES SERVER & LIVE-SYSTEM ACQUISITION
CPR PART 35 EXPERT REPORT S FULL CHAIN-OF-CUSTODY DOCUMENTATION
§ CONTENTS
In this guide
01 Executive summary
02 The problem in plain English: everyone's drive, no one's machine
03 How server collection differs from device imaging
04 What the server records: permissions, audit and metadata
05 Snapshots, previous versions and deleted files
06 Attribution on shared systems
07 The collection playbook
08 Worked examples
09 Common mistakes and technical limitations
10 Questions to ask · Suggested wording
11 Checklist and red flags · When to involve a digital forensic expert
12 Frequently asked questions
13 Glossary · References · Disclaimer · How a specialist laboratory can assist
§ 01 · ORIENTATION
Executive summary
THE HEADLINE POINT: COLLECTTHEFILES, THEHISTORYANDTHECONTEXT, ORTHE
COLLECTIONANSWERSNOTHING
§ 02 · FIRST PRINCIPLES
The problem in plain English: everyone's drive, no one's
machine
§ 03 · THEDIFFERENCESTHATMATTER
How server collection differs from device imaging