A forensic report should do more than list technical findings. It should explain the instruction, evidence examined, methods used, results obtained and the limits of any conclusions in language appropriate for the intended audience.
Instruction and scope
The report should identify the questions asked and the material made available. This helps the reader understand what the examination did - and did not - attempt to establish.
Evidence and methodology
Devices, files, accounts and datasets should be identified, together with relevant acquisition and examination methods. Technical detail should be sufficient to make the process understandable and reproducible where appropriate.
Findings and chronology
Important findings should be linked to their source and presented in a logical sequence. Timelines, tables and exhibits can make complex material easier to follow.
Limitations and conclusions
A defensible report makes uncertainty explicit. Missing data, inaccessible devices, incomplete logs and alternative explanations should not be hidden.
- Case instructions and correspondence
- Evidence inventory
- Acquisition notes
- Analysis results and working notes
- Relevant screenshots or exhibits
- Versioned final report and supporting schedules
- Presenting assumptions as established fact
- Using technical jargon without explanation
- Omitting limitations that affect interpretation
- Including irrelevant private material simply because it was available
