Virtual Machines As Evidence
18 pages · 23 min read
Virtual machines present unique challenges and opportunities as evidence in UK litigation.
- Servers, NAS and virtual environments
This guide addresses the evidential value of virtual machines, including VMware and Hyper-V, and the recovery of historical states from virtual disks and snapshots.
Guide · 18 pages · 23 min read · Published 2026-08-30
A virtual machine (VM) is a computer that exists as a file, offering a unique and often critical source of evidence in digital investigations. Unlike physical hardware, a VM's entire state, including its operating system, applications, and data, can be encapsulated within a set of files. This characteristic allows for the capture of a perfect copy through a single file operation, but also enables its perfect disappearance. Understanding the anatomy of a VM, encompassing its disks, snapshots, memory, and configuration, is fundamental to its evidential use.
This guide, prepared by the Computer Forensics Lab e-discovery team, sets out to demystify virtual machines for UK litigators, in-house counsel, and investigators. It covers the defensible acquisition of VMs, the recovery of historical states through snapshot chains and backups, and the significance of the hypervisor's own record, including lifecycle logs and attribution data. The guide also explores the complexities of hidden and deleted VMs, and where else evidence might reside within the source architecture, such as backup replicas and export logs.
Practitioners can use this guide to navigate the challenges and opportunities presented by virtual machine evidence. It provides worked examples, details common mistakes and technical limitations, and offers suggested wording for questions to ask clients, opponents, and forensic providers. A checklist and red flags are included to assist in identifying when to involve a digital forensic expert, ensuring a robust and defensible approach to virtual machine evidence in legal proceedings.
Read this guide on your phone, browse guides by topic or go back to the full PDF library.
18 pages · 23 min read
Virtual machines present unique challenges and opportunities as evidence in UK litigation.
Published by Computer Forensics Lab on 2026-08-30. Original material of the practice, free to read, cite and download. The authority behind this subject is ACPO/NPCC Good Practice Guide for Digital Evidence, which you should read alongside this guide. See every guide's author and source.
Prefer a PDF that matches this page exactly? Download the current text as a PDF, generated from the current wording of the guide, including any later corrections.
VIRTUALMACHINEEVIDENCE · A GUIDE FOR UK LAWYERS Virtual Machines as Evidence VMware, Hyper-V, Snapshots, Virtual Disks and the Recovery of Historical States COMPUTER FORENSICS LAB
§ ABOUT THE AUTHOR PREPARED BY COMPUTER FORENSICS LAB E-DISCOVERY TEAM FULL CHAIN-OF-CUSTODY DOCUMENTATION
§ CONTENTS In this guide 01 Executive summary 02 The problem in plain English: the computer that is a file 03 The anatomy of a VM: disks, snapshots, memory, configuration 04 Acquiring virtual machines defensibly 05 Historical states: snapshot chains, backups and rollback 06 The hypervisor's own record: lifecycle, logs and attribution 07 Hidden and deleted VMs 08 Source architecture: where else the evidence lives 09 Worked examples 10 Common mistakes and technical limitations 11 Questions to ask · Suggested wording 12 Checklist and red flags · When to involve a digital forensic expert 13 Frequently asked questions 14 Glossary · References · Disclaimer · How a specialist laboratory can assist
§ 01 · ORIENTATION Executive summary THE HEADLINE POINT: APERFECTCOPYISONEFILEOPERATIONAWAY, AND SO IS A PERFECTDISAPPEARANCE
§ 02 · FIRST PRINCIPLES The problem in plain English: the computer that is a file
§ 03 · ANATOMY The anatomy of a VM: disks, snapshots, memory, configuration
§ 04 · ACQUISITION Acquiring virtual machines defensibly
§ 05 · TIMETRAVEL Historical states: snapshot chains, backups and rollback
§ 06 · ONEFLOORUP The hypervisor's own record: lifecycle, logs and attribution
§ 07 · THECONCEALEDANDTHEDESTROYED Hidden and deleted VMs
§ 08 · THEWIDERMAP Source architecture: where else the evidence lives EVIDENCE EXTERNAL VM / BACKUP REPLICA / HYPERVISOR DELETED / CHAIN CATALOGUE EXPORT LOGS RECOVERABLE GUEST'S FOOTPRINT
§ 09 · IN THE WILD Worked examples EXAMPLE1 · THEROLLED - BACKWEEK EXAMPLE2 · THECOMPANYONAPORTABLEDRIVE EXAMPLE3 · THEDELETEDGUESTANDTHEBACKUPCATALOGUE
§ 10 · WHEREITGOESWRONG Common mistakes and technical limitations Common mistakes Technical limitations
§ 11 · INTERROGATORIES & DRAFTING AIDS Questions to ask · Suggested wording Ask your client Ask your opponent Ask your e Discovery / forensic provider SUGGESTED WORDING · INSTRUCTIONFORAVMEXAMIN AT ION
§ 12 · QUICK CONTROL Checklist and red flags · When to involve a digital forensic expert The VM evidence checklist Red flags When to involve a digital forensic expert
§ 13 · COMMON QUESTIONS Frequently asked questions Is a copied VM as good as imaging the original server? Someone reverted the machine to an old snapshot. Is the interval gone? A VM was deleted before we could act. What are the odds? Can we make the other side disclose hypervisor logs and backup catalogues? The disputed VM runs in Azure/AWS, not on our opponent's own servers. Does the approach change? We suspect an employee ran a hidden VM on their laptop. What should we ask for?
§ 14 · REFERENCE Glossary Sources and authoritative references DISCLAIMER
§ HOW A SPECIALIST LABORATORY CAN ASSIST Working with Computer Forensics Lab Speak to a forensic examiner, not a salesperson. INSTRUCTTHELAB NEWENQUIRIESEMAILE - DISCOVERY
18 pages · 26 min read
This guide for UK lawyers addresses the complexities of recovering data from RAID arrays, Network Attached Storage, and servers.
17 pages · 23 min read
Understanding where digital evidence truly resides in virtual desktop infrastructure (VDI) and remote desktop environments is crucial for UK litigators.
Whether you are responding to a regulator, preparing for disclosure, or scoping an internal investigation, start the chain of custody with a short, confidential conversation.