Back to product
PUBLIC CHECKLIST

Forensic Acquisition Documentation Checklist

The technical image or export is only part of the record. Document the conditions and decisions required for another qualified examiner to understand what was acquired and how.

PUBLIC OPERATIONAL REFERENCE

Record before acquisition

  • Source item number, description, identifiers, condition, and custody status.
  • Power, lock, mount, network, encryption, and write-protection state.
  • Authority, requested scope, exclusions, and known constraints.
  • Examiner, workstation identifier, date, start time, timezone, and clock verification.
  • Acquisition method, interface, adapters, destination media, and expected output format.

Record during and after acquisition

  • Tool name, version, settings, commands, logs, screenshots, and relevant licensing mode.
  • Errors, retries, interruptions, timeouts, skipped data, and deviations from procedure.
  • Start time, completion time, source hash when available, destination hash, and verification result.
  • Output filenames, paths, media identifiers, storage location, and access controls.
  • Any transformation, decompression, conversion, repair, or normalization applied to the acquired output.
Interpretation limit

If acquisition is partial or a hash cannot be obtained, state that limitation directly and explain the verification method used instead.

Continue with the complete workflow

Public references are starting points. DFIR Field Toolkit connects operational references with an encrypted local case record, evidence inventory, field forms, amendments, and exports.

Create one complete case free or explore the synthetic product demo.