Well-intentioned actions before an examination can change or destroy evidence. If a device may need forensic review, the safest approach is usually to minimise unnecessary interaction and record its current condition.
Do not “tidy up” the device
Avoid deleting files, clearing browser history, uninstalling applications or reorganising folders. These actions alter the evidence and may remove information that helps explain events.
Record the current state
Note whether the device is on or off, connected to a network, locked or unlocked, and whether any important application is currently open. Photographing the screen can be useful in some circumstances.
Provide useful context
Prepare the case reference, relevant date range, names or identifiers, applications of interest and the questions you want answered. This helps focus the examination.
Keep accessories and credentials available
Chargers, unusual cables, encryption keys or passcodes may be important where you are lawfully authorised to provide them. Do not write passwords on the device itself.
- The original device or storage media
- Relevant chargers and proprietary adapters
- Existing backups
- Device identifiers and ownership records
- Lawfully available passcodes or encryption keys
- A short written case scope
- Running antivirus or cleanup tools
- Operating-system updates
- Factory resets or password-reset procedures
- Testing recovery utilities on the original media
