Limits of digital evidence
What a forensic examination can establish, what it cannot, and why in each case. I publish it before the engagement, because the reach of a finding is the part that gets attacked.
- Document
- WW-F-006
- Version
- 1.0
- Issued
- 2026-09-11
- Last revised
- 2026-09-11
- Scope
- Reach and limits of findings
- Authority
- Principal
Six places digital evidence stops
Every finding has a reach. Past it, one artefact supports two or three explanations at once. These six are where cases run out of road.
| The limit | What the evidence does reach | What this does not establish |
|---|---|---|
| A device — or an account — is not a person | What the machine did, under which session or credential. | Who was at the keyboard. Shared logins, remote tools and malware look alike on disk. |
| Intent is a finding for the court | What was destroyed, when, by what mechanism, and whether retention would have taken it anyway. | Intent to deprive under Rule 37(e)(2). Where expiry and destruction look alike, I say so. |
| Timestamps are precise, not accurate | Times as each clock recorded them, from a named field, with the offset printed. | The true time, where one clock is the only source. "Created" never means authored. |
| Absence is not evidence of absence | That an artefact is missing where comparable events reliably have one. | That nothing happened, or that it was hidden. Rotation, retention and SSD trim delete on a schedule. |
| USB records show attachment, not copying | That a device reporting a given identity was attached, and usually when. | That anything was copied, which way, or how much. USBSTOR serials repeat across production runs. |
| Deletion is decided by the medium | What the medium and encryption state permit, and which backup or custodian is the better prospect. | Recovery from encrypted flash. The controller erases on its own schedule. |
Recovery attempts bill the same whether or not they return anything, so I say what the medium permits first.
Cloud logs record access, not content. In Microsoft 365, MailItemsAccessed — the record that governs what must be notified — depends on audit tier and is absent from many tenants that assume they have it. Enabling it mid-incident logs forward only.
Automated output is not a finding. Tools disagree and versions change behaviour, so I read behind the parse to the structure itself and record the tool and version.
What an examination does establish
You end up holding a written report, each finding carrying its own reach in this language, the verified image, and where needed a declaration.
| What I can establish | On what basis | What this does not establish |
|---|---|---|
| That a copy corresponds to its source | A digest taken at acquisition, re-verified before analysis and before production. | That the source was unaltered before I reached it. |
| The sequence of events | Ordering corroborated across independent artefacts, often sound where absolute times are not. | The cause, or the person behind it. |
| That material was removed, and how | Journal and recycle records, wipe-utility artefacts, reset records, retention rules. | Intent, which is for the court. |
| That an account behaved unlike itself | A baseline built from the account's own history. | Who held the credential. |
| Whether an opposing report is supported by its own material | Each finding marked supported, partly supported, unsupported or untestable. | That the conclusion is wrong. |
Where a matter requires an attribution opinion or a certified examiner, that is stated in the engagement letter before work starts.
Ask a question the evidence can answer
Most instructions can be reshaped into something the data reaches. I do that on the scoping call, which is not charged for.
- "Did he take our client list?" → What movement of these named files is recorded, between these dates, across these devices and accounts?
- "Prove this email is genuine." → Is the produced copy consistent with the records held by both mail systems?
- "Who was at the keyboard?" → What would an attribution opinion require, and does that material exist?
I report what the evidence supports, including when it supports nothing, or supports the other side. The fee is the same either way.
The rate is fixed before I look at anything, so I have no reason to stretch a finding past its reach.
Ring me on 917-217-7975 and I will tell you whether this is even a forensics problem. That call is free, and so is the one that ends with me saying you do not need an examiner. Or use the contact form.