Method
Write-blocked acquisition, two independent hashes, and a custody record written as the work happens — set out so an examiner retained against me could repeat it and check the result.
- Document
- WW-F-005
- Version
- 1.0
- Issued
- 2026-09-11
- Last revised
- 2026-09-11
- Scope
- Acquisition to destruction procedure
- Authority
- Principal
What you end up holding
- A signed report — each opinion, its basis, the data considered and the method applied, traceable to something verified.
- A verified forensic image, hash-matched at acquisition, before analysis and before production. $950 up to 2 TB, per device.
- The acquisition log and imaging worksheet — tool, version, operator, timestamps, blocker make and firmware.
- A chain of custody record, closed by return or a certificate of destruction.
Examination is $425/hr against a written ceiling; the scoping call is no charge. Full schedule on rates, report format on specimen report.
The four things that make it hold
Authority first. Before a device is connected to anything, I record who authorises access, to what, on what basis. Where that is unclear I decline — a credential that works is not authority to use it.
Write blocking, and proof of it. The source is presented read-only through a hardware blocker where the interface permits, and I confirm and record the blocked state before imaging starts. A blocker on the bench is not a blocker in line.
Two digests, two tools. One over the bytes as read, in the pass that writes the image; a second over the stored image afterwards, preferably with a different tool. Only the comparison means anything.
A custody record written as it happens. Receipt, every custodian, every transfer, storage, disposal.
The verification, shown
[SPECIMEN — NOT A REAL MATTER]
Identifiers and digests below are invented. The commands are the ones I run.
$ sudo blockdev --getro /dev/sdb
1
$ sudo dc3dd if=/dev/sdb hof=/evi/WW-S-0000/001.raw \
hash=sha256 log=/evi/WW-S-0000/001.acq.log
500107862016 bytes ( 466 G ) copied ( 100% ), 4231.1 s, 113 M/s
9d2a35b6a225ec122410d86b12cf875bf04215e5608dea39034cbb8bfa192e3a (sha256)
# Separate pass, separate tool, source detached.
$ sha256sum /evi/WW-S-0000/001.raw
9d2a35b6a225ec122410d86b12cf875bf04215e5608dea39034cbb8bfa192e3a /evi/WW-S-0000/001.raw
SHA-256 is the primary algorithm; MD5 appears only where a tool emits it, never as a security claim. Analysis runs on a working copy, verified against the master the same way. A match proves the image corresponds to the source as read — nothing about the source before I arrived, nor about content or authorship.
When a digest does not match
Work stops. Nothing is analysed from that image, and the failure goes into the report with both digests, the tools and the time, resolved or not. Then I narrow it: per-segment digests, a fresh acquisition where the source is still readable, enumerated bad sectors where the medium is failing. A failing drive does not destroy the evidence. A quiet second attempt that replaces the first with no record does.
Where write blocking cannot be used
Live memory, a production system that cannot be taken down, most mobile extractions, cloud collected over an authenticated session. Each alters something. Soundness then comes from the record: method, tool version, a digest at the earliest useful point, and a plain statement of what was altered.
What each stage does and does not establish
| Stage | What it establishes | What this does not establish |
|---|---|---|
| Authority and scope | Who authorised access to what, recorded before anything was connected. | That the authority was validly held. |
| Write-blocked acquisition | The source was read-only and the image corresponds to the source as read. | Anything before my custody began. |
| Live acquisition | The state of a running system at a stated moment, memory and encryption included. | A clean capture; it writes to the system. |
| Hash verification SHA-256 primary | Image and working copies are byte-identical to what was read. | Content, authorship or truth. |
| Mobile and cloud collection | What was obtainable at that patch level, or retained by that tenant, that day. | Completeness; both are partial by construction. |
| Chain of custody | Where the item was, in whose hands, from receipt to disposal. | Integrity before receipt; it is not a substitute for the hash. |
| Examination | What the artefacts show: what existed, what changed, when, by what mechanism. | Who was at the keyboard. |
| Return or destruction | Re-verified on withdrawal, disposed of on written instruction, certificate issued. | Nothing about copies held by anyone else. |
| Reporting | The opinions, their bases, the data considered and the method applied. | Admissibility; that is the court's decision. |
The image and its logs are what FRE 902(14) and 902(13) contemplate, with a certification: that removes the need for live foundation testimony on authenticity, and nothing else.
Standards worked to
NIST SP 800-86 for sequence and order of volatility; ISO/IEC 27037 for auditability, repeatability, reproducibility and justifiability; SWGDE practice documents, cited by version. Guidance I work to, not certificates I hold — I do not call work "ISO 27037 compliant". Where a matter requires a certified examiner, an accredited laboratory or a licence, that is identified at scoping and stated in the engagement letter, or I decline the matter.
Before you pay for an attempt
I will tell you when something is unlikely to be recoverable: deleted data on encrypted flash often is not, an encrypted volume without a key is not opened by effort, a locked modern handset may not be reachable at any price. I report findings that do not help you at the same rate, because the rate does not move with what I find.
Ring me on 917-217-7975 and I will tell you whether this is even a forensics problem, and if it is, what the first hour should do.