E-Discovery and Litigation Data
Collection and Processing
Forensic collection creates a bit-level image or a targeted copy preserving file metadata, using write-blocking and hash verification to establish that the copy matches the source.
It is performed by trained examiners and documented for chain of custody.
Alternative Names:
Forensic Imaging, Defensible Collection
Why it Matters?
Forensic methods are necessary where metadata matters, where deleted content may be recoverable, or where the collection's integrity is likely to be challenged. Full imaging is not required for most matters and is expensive, so targeted forensic collection of specific accounts and devices is the common middle ground. The decision should be made deliberately, since converting to forensic methods after a self-collection is rarely possible.
Frequently Confused with
Related terms
Frequently asked questions
When is forensic collection necessary?
Is full imaging always required?


