Digital evidence is altered by normal use. Booting a computer updates records. Opening a file may change metadata. Forwarding an email changes its headers. Removing a cloud license can change retention. A defensible response begins with a short pause to identify the source, its state, and the least disruptive preservation method.
Treat the original as a source, not a workspace
Do not conduct exploratory review on the only copy. Record identifiers and condition, then preserve through an appropriate forensic image, native export, provider hold, or targeted collection. Work from a validated copy where the source and acquisition method permit. Some cloud, mobile, volatile, or live-system work cannot produce a traditional forensic image; in those cases, record the access, method, time, unavoidable changes, and resulting limitations.
Screenshots preserve appearance, not the full record
A screenshot can show what a user saw, but it often omits metadata, hidden fields, message routing, edit history, file structure, and surrounding context. Preserve the screenshot when it matters, then obtain the native message, file, database, device, or platform export where possible.
- Do not forward questioned email as the sole preservation method
- Do not factory-reset, reimage, or reassign a device before preservation
- Do not remove licenses or delete accounts without checking retention effects
- Do not mix evidence from several sources without provenance
- Do not promise that an absent artifact proves an event never occurred
Write down the exception while it is happening
Access failures, unsupported devices, missing logs, corrupted media, overwritten records, unavailable custodians, and emergency changes belong in the preservation record. A contemporaneous limitation is manageable. A gap discovered months later is much harder to explain.