Not every digital forensics investigation requires a device to be shipped to a lab. In many matters, a remote logical collection (which captures active, accessible data, such as documents, emails, and text messages, rather than the entire device) can provide the information needed quickly and with minimal disruption. But in other cases, when the stakes are higher, a more comprehensive in-lab examination may be necessary. Choosing between the two comes down to the circumstances of the investigation, the device, and the evidence you need to uncover.
Remote logical collections allow forensic investigators to collect available data from a device without requiring the physical device to be brought into a lab. When the custodian is cooperative and the investigation is relatively straightforward, this approach can be an efficient way to preserve and collect relevant information.
Remote collections can be particularly useful for:
The tradeoff is that a logical collection generally provides access to a more limited set of data. Depending on the device, operating system, applications and collection tools available, certain system-level artifacts, application databases or deleted data may not be accessible. These limitations resolve to the “logical” level of the cellphone where unencrypted data such as photos and the SMS data (texting/ iMessage) resides. Encrypted applications like Signal, Telegram, Snapchat, etc. are not logically exportable due to the nature of the security. These limitations are important to know.
When an investigation involves significant risk, suspected misconduct, or the potential loss or concealment of evidence, a deeper level of forensic collection may be warranted. In-lab full file system (FFS) and physical collections, along with certain expert onsite collections, use specialized forensic tools and techniques that are not available through remote logical collections.
Depending on the device, operating system, and available tools, these methods can provide access to additional evidence, including system-level databases, application data, encrypted communications, configuration information, and, in some cases, traces of deleted data.
A deeper collection may be particularly valuable for investigations involving:
These collections also give forensic investigators greater control over the device and the preservation and examination process. However, they typically require more time, specialized expertise, and physical access to the device – and may come at a higher cost than a remote logical collection. The right choice ultimately depends on the risk, stakes, device, evidence needed, and level of access required.
The right approach depends on the risk and stakes of the matter. So, before deciding how to collect a device, consider:
Digital forensics is not a one-size-fits-all process. A remote logical collection may be exactly what a straightforward investigation requires, while a high-stakes matter may call for the deeper access and control of an in-lab forensic acquisition. The key is determining what evidence you may need before you decide how to collect it.
Working with an experienced digital forensics team can help attorneys and legal teams evaluate the matter, understand the available collection options, and select an approach that balances evidence, defensibility, cost and disruption.
Have a device that needs to be collected? Connect with Avalon’s digital forensics team to discuss the right approach for your investigation.