Not every digital forensics investigation requires a device to be shipped to a lab. In many matters, a remote logical collection (which captures active, accessible data, such as documents, emails, and text messages, rather than the entire device) can provide the information needed quickly and with minimal disruption. But in other cases, when the stakes are higher, a more comprehensive in-lab examination may be necessary. Choosing between the two comes down to the circumstances of the investigation, the device, and the evidence you need to uncover.
Remote Logical Collections: Faster and Less Disruptive
Remote logical collections allow forensic investigators to collect available data from a device without requiring the physical device to be brought into a lab. When the custodian is cooperative and the investigation is relatively straightforward, this approach can be an efficient way to preserve and collect relevant information.
Remote collections can be particularly useful for:
- HR investigations and policy violations where the scope of the inquiry is limited
- Lower-risk disputes where a targeted collection is appropriate
- Cooperative custodians who can provide access to the device and participate in the collection process
- Time-sensitive matters where minimizing disruption to the custodian or business is important
- Readily accessible compliance – if the text messages are viewable and need to be produced, targeting these messages with forensic tools is always a better choice than producing screenshots or printouts of digital data
The tradeoff is that a logical collection generally provides access to a more limited set of data. Depending on the device, operating system, applications and collection tools available, certain system-level artifacts, application databases or deleted data may not be accessible. These limitations resolve to the “logical” level of the cellphone where unencrypted data such as photos and the SMS data (texting/ iMessage) resides. Encrypted applications like Signal, Telegram, Snapchat, etc. are not logically exportable due to the nature of the security. These limitations are important to know.
In-Lab Full File System & Expert Onsite Collections = Deeper Examination
When an investigation involves significant risk, suspected misconduct, or the potential loss or concealment of evidence, a deeper level of forensic collection may be warranted. In-lab full file system (FFS) and physical collections, along with certain expert onsite collections, use specialized forensic tools and techniques that are not available through remote logical collections.
Depending on the device, operating system, and available tools, these methods can provide access to additional evidence, including system-level databases, application data, encrypted communications, configuration information, and, in some cases, traces of deleted data.
A deeper collection may be particularly valuable for investigations involving:
- Intellectual property theft or suspected data exfiltration
- Serious employee misconduct
- Encrypted application communications
- Attempts to delete, conceal, or manipulate evidence
- Matters where a more comprehensive examination of the device is warranted
These collections also give forensic investigators greater control over the device and the preservation and examination process. However, they typically require more time, specialized expertise, and physical access to the device – and may come at a higher cost than a remote logical collection. The right choice ultimately depends on the risk, stakes, device, evidence needed, and level of access required.
Which Collection Method Should You Choose?
The right approach depends on the risk and stakes of the matter. So, before deciding how to collect a device, consider:
- Risk – Is this a routine HR investigation or a matter involving suspected misconduct, theft, or evidence destruction? Is this potentially going to litigation? Do I need to uncover deleted data, user-interactions on the phone (distracted driving, using at work, geolocating), or do I need to safely produce obvious communications?
- Stakes – How significant are the potential legal, financial, or reputational consequences?
- Control of the device – Is the device in your possession, or does the custodian still control it? Do we have a legal right to the device? Is the PIN code known? Advanced services like unlocking may be available on special occasions.
- Device and OS – What device, operating system, and applications are involved, and what collection methods do they support?
- Evidence needed – Do you need targeted user data, or could system-level artifacts, application databases, or deleted traces be important?
- Cost and timing – How quickly is the information needed, and does the matter justify a more comprehensive examination?
Making the Right Collection Choice
Digital forensics is not a one-size-fits-all process. A remote logical collection may be exactly what a straightforward investigation requires, while a high-stakes matter may call for the deeper access and control of an in-lab forensic acquisition. The key is determining what evidence you may need before you decide how to collect it.
Working with an experienced digital forensics team can help attorneys and legal teams evaluate the matter, understand the available collection options, and select an approach that balances evidence, defensibility, cost and disruption.
Have a device that needs to be collected? Connect with Avalon’s digital forensics team to discuss the right approach for your investigation.