Incident in progress What to do in the first hour → Preserve first. Several ordinary responses destroy the evidence permanently.
Wirewalk Forensics and Security

Method

Write-blocked acquisition, two independent hashes, and a custody record written as the work happens — set out so an examiner retained against me could repeat it and check the result.

Document
WW-F-005
Version
1.0
Issued
2026-09-11
Last revised
2026-09-11
Scope
Acquisition to destruction procedure
Authority
Principal

What you end up holding

  • A signed report — each opinion, its basis, the data considered and the method applied, traceable to something verified.
  • A verified forensic image, hash-matched at acquisition, before analysis and before production. $950 up to 2 TB, per device.
  • The acquisition log and imaging worksheet — tool, version, operator, timestamps, blocker make and firmware.
  • A chain of custody record, closed by return or a certificate of destruction.

Examination is $425/hr against a written ceiling; the scoping call is no charge. Full schedule on rates, report format on specimen report.

The four things that make it hold

Authority first. Before a device is connected to anything, I record who authorises access, to what, on what basis. Where that is unclear I decline — a credential that works is not authority to use it.

Write blocking, and proof of it. The source is presented read-only through a hardware blocker where the interface permits, and I confirm and record the blocked state before imaging starts. A blocker on the bench is not a blocker in line.

Two digests, two tools. One over the bytes as read, in the pass that writes the image; a second over the stored image afterwards, preferably with a different tool. Only the comparison means anything.

A custody record written as it happens. Receipt, every custodian, every transfer, storage, disposal.

The verification, shown

[SPECIMEN — NOT A REAL MATTER]

Identifiers and digests below are invented. The commands are the ones I run.

$ sudo blockdev --getro /dev/sdb
1

$ sudo dc3dd if=/dev/sdb hof=/evi/WW-S-0000/001.raw \
      hash=sha256 log=/evi/WW-S-0000/001.acq.log
   500107862016 bytes ( 466 G ) copied ( 100% ), 4231.1 s, 113 M/s
   9d2a35b6a225ec122410d86b12cf875bf04215e5608dea39034cbb8bfa192e3a (sha256)

# Separate pass, separate tool, source detached.
$ sha256sum /evi/WW-S-0000/001.raw
9d2a35b6a225ec122410d86b12cf875bf04215e5608dea39034cbb8bfa192e3a  /evi/WW-S-0000/001.raw

SHA-256 is the primary algorithm; MD5 appears only where a tool emits it, never as a security claim. Analysis runs on a working copy, verified against the master the same way. A match proves the image corresponds to the source as read — nothing about the source before I arrived, nor about content or authorship.

When a digest does not match

Work stops. Nothing is analysed from that image, and the failure goes into the report with both digests, the tools and the time, resolved or not. Then I narrow it: per-segment digests, a fresh acquisition where the source is still readable, enumerated bad sectors where the medium is failing. A failing drive does not destroy the evidence. A quiet second attempt that replaces the first with no record does.

Where write blocking cannot be used

Live memory, a production system that cannot be taken down, most mobile extractions, cloud collected over an authenticated session. Each alters something. Soundness then comes from the record: method, tool version, a digest at the earliest useful point, and a plain statement of what was altered.

What each stage does and does not establish

Stage ledger
StageWhat it establishesWhat this does not establish
Authority and scopeWho authorised access to what, recorded before anything was connected.That the authority was validly held.
Write-blocked acquisitionThe source was read-only and the image corresponds to the source as read.Anything before my custody began.
Live acquisitionThe state of a running system at a stated moment, memory and encryption included.A clean capture; it writes to the system.
Hash verification
SHA-256 primary
Image and working copies are byte-identical to what was read.Content, authorship or truth.
Mobile and cloud collectionWhat was obtainable at that patch level, or retained by that tenant, that day.Completeness; both are partial by construction.
Chain of custodyWhere the item was, in whose hands, from receipt to disposal.Integrity before receipt; it is not a substitute for the hash.
ExaminationWhat the artefacts show: what existed, what changed, when, by what mechanism.Who was at the keyboard.
Return or destructionRe-verified on withdrawal, disposed of on written instruction, certificate issued.Nothing about copies held by anyone else.
ReportingThe opinions, their bases, the data considered and the method applied.Admissibility; that is the court's decision.

The image and its logs are what FRE 902(14) and 902(13) contemplate, with a certification: that removes the need for live foundation testimony on authenticity, and nothing else.

Standards worked to

NIST SP 800-86 for sequence and order of volatility; ISO/IEC 27037 for auditability, repeatability, reproducibility and justifiability; SWGDE practice documents, cited by version. Guidance I work to, not certificates I hold — I do not call work "ISO 27037 compliant". Where a matter requires a certified examiner, an accredited laboratory or a licence, that is identified at scoping and stated in the engagement letter, or I decline the matter.

Before you pay for an attempt

I will tell you when something is unlikely to be recoverable: deleted data on encrypted flash often is not, an encrypted volume without a key is not opened by effort, a locked modern handset may not be reachable at any price. I report findings that do not help you at the same rate, because the rate does not move with what I find.

Ring me on 917-217-7975 and I will tell you whether this is even a forensics problem, and if it is, what the first hour should do.