Incident in progress What to do in the first hour → Preserve first. Several ordinary responses destroy the evidence permanently.
Wirewalk Forensics and Security

Limits of digital evidence

What a forensic examination can establish, what it cannot, and why in each case. I publish it before the engagement, because the reach of a finding is the part that gets attacked.

Document
WW-F-006
Version
1.0
Issued
2026-09-11
Last revised
2026-09-11
Scope
Reach and limits of findings
Authority
Principal

Six places digital evidence stops

Every finding has a reach. Past it, one artefact supports two or three explanations at once. These six are where cases run out of road.

The limits that matter
The limitWhat the evidence does reachWhat this does not establish
A device — or an account — is not a personWhat the machine did, under which session or credential.Who was at the keyboard. Shared logins, remote tools and malware look alike on disk.
Intent is a finding for the courtWhat was destroyed, when, by what mechanism, and whether retention would have taken it anyway.Intent to deprive under Rule 37(e)(2). Where expiry and destruction look alike, I say so.
Timestamps are precise, not accurateTimes as each clock recorded them, from a named field, with the offset printed.The true time, where one clock is the only source. "Created" never means authored.
Absence is not evidence of absenceThat an artefact is missing where comparable events reliably have one.That nothing happened, or that it was hidden. Rotation, retention and SSD trim delete on a schedule.
USB records show attachment, not copyingThat a device reporting a given identity was attached, and usually when.That anything was copied, which way, or how much. USBSTOR serials repeat across production runs.
Deletion is decided by the mediumWhat the medium and encryption state permit, and which backup or custodian is the better prospect.Recovery from encrypted flash. The controller erases on its own schedule.

Recovery attempts bill the same whether or not they return anything, so I say what the medium permits first.

Cloud logs record access, not content. In Microsoft 365, MailItemsAccessed — the record that governs what must be notified — depends on audit tier and is absent from many tenants that assume they have it. Enabling it mid-incident logs forward only.

Automated output is not a finding. Tools disagree and versions change behaviour, so I read behind the parse to the structure itself and record the tool and version.

What an examination does establish

You end up holding a written report, each finding carrying its own reach in this language, the verified image, and where needed a declaration.

Capability — with reach
What I can establishOn what basisWhat this does not establish
That a copy corresponds to its sourceA digest taken at acquisition, re-verified before analysis and before production.That the source was unaltered before I reached it.
The sequence of eventsOrdering corroborated across independent artefacts, often sound where absolute times are not.The cause, or the person behind it.
That material was removed, and howJournal and recycle records, wipe-utility artefacts, reset records, retention rules.Intent, which is for the court.
That an account behaved unlike itselfA baseline built from the account's own history.Who held the credential.
Whether an opposing report is supported by its own materialEach finding marked supported, partly supported, unsupported or untestable.That the conclusion is wrong.

Where a matter requires an attribution opinion or a certified examiner, that is stated in the engagement letter before work starts.

Ask a question the evidence can answer

Most instructions can be reshaped into something the data reaches. I do that on the scoping call, which is not charged for.

  • "Did he take our client list?" → What movement of these named files is recorded, between these dates, across these devices and accounts?
  • "Prove this email is genuine." → Is the produced copy consistent with the records held by both mail systems?
  • "Who was at the keyboard?" → What would an attribution opinion require, and does that material exist?

I report what the evidence supports, including when it supports nothing, or supports the other side. The fee is the same either way.

The rate is fixed before I look at anything, so I have no reason to stretch a finding past its reach.

Ring me on 917-217-7975 and I will tell you whether this is even a forensics problem. That call is free, and so is the one that ends with me saying you do not need an examiner. Or use the contact form.

Method · rates · scope.