§ Guide

Virtual Machines As Evidence

This guide addresses the evidential value of virtual machines, including VMware and Hyper-V, and the recovery of historical states from virtual disks and snapshots.

Ref · E-D · 2026 · §LIBClass · ConfidentialJuris · England & WalesStatus · Active

Guide · 18 pages · 23 min read · Published 2026-08-30

A virtual machine (VM) is a computer that exists as a file, offering a unique and often critical source of evidence in digital investigations. Unlike physical hardware, a VM's entire state, including its operating system, applications, and data, can be encapsulated within a set of files. This characteristic allows for the capture of a perfect copy through a single file operation, but also enables its perfect disappearance. Understanding the anatomy of a VM, encompassing its disks, snapshots, memory, and configuration, is fundamental to its evidential use.

This guide, prepared by the Computer Forensics Lab e-discovery team, sets out to demystify virtual machines for UK litigators, in-house counsel, and investigators. It covers the defensible acquisition of VMs, the recovery of historical states through snapshot chains and backups, and the significance of the hypervisor's own record, including lifecycle logs and attribution data. The guide also explores the complexities of hidden and deleted VMs, and where else evidence might reside within the source architecture, such as backup replicas and export logs.

Practitioners can use this guide to navigate the challenges and opportunities presented by virtual machine evidence. It provides worked examples, details common mistakes and technical limitations, and offers suggested wording for questions to ask clients, opponents, and forensic providers. A checklist and red flags are included to assist in identifying when to involve a digital forensic expert, ensuring a robust and defensible approach to virtual machine evidence in legal proceedings.

Read this guide on your phone, browse guides by topic or go back to the full PDF library.

§ Credit and source

Published by Computer Forensics Lab on 2026-08-30. Original material of the practice, free to read, cite and download. The authority behind this subject is ACPO/NPCC Good Practice Guide for Digital Evidence, which you should read alongside this guide. See every guide's author and source.

§ Read Virtual Machines As Evidence

Download the PDF

Prefer a PDF that matches this page exactly? Download the current text as a PDF, generated from the current wording of the guide, including any later corrections.

Page 1

VIRTUALMACHINEEVIDENCE · A GUIDE FOR UK LAWYERS Virtual Machines as Evidence VMware, Hyper-V, Snapshots, Virtual Disks and the Recovery of Historical States COMPUTER FORENSICS LAB

§ ABOUT THE AUTHOR PREPARED BY COMPUTER FORENSICS LAB E-DISCOVERY TEAM FULL CHAIN-OF-CUSTODY DOCUMENTATION

§ CONTENTS In this guide 01 Executive summary 02 The problem in plain English: the computer that is a file 03 The anatomy of a VM: disks, snapshots, memory, configuration 04 Acquiring virtual machines defensibly 05 Historical states: snapshot chains, backups and rollback 06 The hypervisor's own record: lifecycle, logs and attribution 07 Hidden and deleted VMs 08 Source architecture: where else the evidence lives 09 Worked examples 10 Common mistakes and technical limitations 11 Questions to ask · Suggested wording 12 Checklist and red flags · When to involve a digital forensic expert 13 Frequently asked questions 14 Glossary · References · Disclaimer · How a specialist laboratory can assist

§ 01 · ORIENTATION Executive summary THE HEADLINE POINT: APERFECTCOPYISONEFILEOPERATIONAWAY, AND SO IS A PERFECTDISAPPEARANCE

§ 02 · FIRST PRINCIPLES The problem in plain English: the computer that is a file

§ 03 · ANATOMY The anatomy of a VM: disks, snapshots, memory, configuration

Page 2

§ 04 · ACQUISITION Acquiring virtual machines defensibly

§ 05 · TIMETRAVEL Historical states: snapshot chains, backups and rollback

§ 06 · ONEFLOORUP The hypervisor's own record: lifecycle, logs and attribution

§ 07 · THECONCEALEDANDTHEDESTROYED Hidden and deleted VMs

§ 08 · THEWIDERMAP Source architecture: where else the evidence lives EVIDENCE EXTERNAL VM / BACKUP REPLICA / HYPERVISOR DELETED / CHAIN CATALOGUE EXPORT LOGS RECOVERABLE GUEST'S FOOTPRINT

§ 09 · IN THE WILD Worked examples EXAMPLE1 · THEROLLED - BACKWEEK EXAMPLE2 · THECOMPANYONAPORTABLEDRIVE EXAMPLE3 · THEDELETEDGUESTANDTHEBACKUPCATALOGUE

Page 3

§ 10 · WHEREITGOESWRONG Common mistakes and technical limitations Common mistakes Technical limitations

§ 11 · INTERROGATORIES & DRAFTING AIDS Questions to ask · Suggested wording Ask your client Ask your opponent Ask your e Discovery / forensic provider SUGGESTED WORDING · INSTRUCTIONFORAVMEXAMIN AT ION

§ 12 · QUICK CONTROL Checklist and red flags · When to involve a digital forensic expert The VM evidence checklist Red flags When to involve a digital forensic expert

§ 13 · COMMON QUESTIONS Frequently asked questions Is a copied VM as good as imaging the original server? Someone reverted the machine to an old snapshot. Is the interval gone? A VM was deleted before we could act. What are the odds? Can we make the other side disclose hypervisor logs and backup catalogues? The disputed VM runs in Azure/AWS, not on our opponent's own servers. Does the approach change? We suspect an employee ran a hidden VM on their laptop. What should we ask for?

§ 14 · REFERENCE Glossary Sources and authoritative references DISCLAIMER

§ HOW A SPECIALIST LABORATORY CAN ASSIST Working with Computer Forensics Lab Speak to a forensic examiner, not a salesperson. INSTRUCTTHELAB NEWENQUIRIESEMAILE - DISCOVERY

§ Related documents
Instruct the practice

Bring us in early. Defensibility is built, not retrofitted.

Whether you are responding to a regulator, preparing for disclosure, or scoping an internal investigation, start the chain of custody with a short, confidential conversation.

WhatsApp