Skip to content
HomeResourcesPreparing a Device for Forensic Examination
Before Examination

Preparing a Device for Forensic Examination

What to do - and what not to do - before handing over a computer, phone or storage device.

5 min readPractical forensic guidanceUpdated September 2026
Preparing a Device for Forensic Examination
Evidence firstPreserve the source. Understand the context.

Well-intentioned actions before an examination can change or destroy evidence. If a device may need forensic review, the safest approach is usually to minimise unnecessary interaction and record its current condition.

Do not “tidy up” the device

Avoid deleting files, clearing browser history, uninstalling applications or reorganising folders. These actions alter the evidence and may remove information that helps explain events.

Record the current state

Note whether the device is on or off, connected to a network, locked or unlocked, and whether any important application is currently open. Photographing the screen can be useful in some circumstances.

Provide useful context

Prepare the case reference, relevant date range, names or identifiers, applications of interest and the questions you want answered. This helps focus the examination.

Keep accessories and credentials available

Chargers, unusual cables, encryption keys or passcodes may be important where you are lawfully authorised to provide them. Do not write passwords on the device itself.

Evidence to preserve
  • The original device or storage media
  • Relevant chargers and proprietary adapters
  • Existing backups
  • Device identifiers and ownership records
  • Lawfully available passcodes or encryption keys
  • A short written case scope
Avoid if possible
  • Running antivirus or cleanup tools
  • Operating-system updates
  • Factory resets or password-reset procedures
  • Testing recovery utilities on the original media
A useful rule: preserve before you clean up, export before logs expire, and document any action that changes the source.