E-Discovery and Litigation Data

Collection and Processing

Forensic Collection

Forensic Collection

Forensic Collection

Forensic collection creates a bit-level image or a targeted copy preserving file metadata, using write-blocking and hash verification to establish that the copy matches the source.

It is performed by trained examiners and documented for chain of custody.

Alternative Names:

Forensic Imaging, Defensible Collection

Why it Matters?

Forensic methods are necessary where metadata matters, where deleted content may be recoverable, or where the collection's integrity is likely to be challenged. Full imaging is not required for most matters and is expensive, so targeted forensic collection of specific accounts and devices is the common middle ground. The decision should be made deliberately, since converting to forensic methods after a self-collection is rarely possible.

Frequently asked questions

When is forensic collection necessary?

Is full imaging always required?