Digital Forensics Foundations: Legal Process, Order of Volatility & Chain of Custody
Digital forensics is the discipline of turning a compromised system into legally defensible evidence: collected, handled, and documented in a way that survives scrutiny later. This chapter lays the foundation, the branches of the field, the legal basis for collecting evidence, and the custody discipline, that every other chapter in this module (disk, Windows artifacts, memory, timeline, network, mobile and cloud, anti-forensics) builds on directly.
The Branches of Digital Forensics
Digital forensics is not one skill, it is a set of related disciplines, each recovering a different kind of evidence from a different kind of source. This module covers five of them in depth, one chapter or more at a time.
| Branch | What It Recovers | Typical Trigger |
|---|---|---|
| Disk / Media Forensics | Deleted files, file system metadata, partition artifacts, slack space | Insider misuse, data theft, ransomware post-mortem |
| Memory Forensics | Running processes, injected code, encryption keys, network connections in memory | Live malware, fileless attacks, credential theft |
| Network Forensics | Packet captures, flow records, DNS and proxy logs, lateral movement traces | Active intrusion, exfiltration, C2 investigation |
| Mobile Forensics | App data, call and message history, location history, device backups | BYOD incidents, HR investigations, device seizure |
| Cloud Forensics | Control-plane logs, object storage history, identity and access logs, snapshot images | Cloud account compromise, misconfigured storage, SaaS abuse |
Legal and Ethical Framework
Evidence that is collected without proper authority, or handled sloppily, can be challenged or thrown out entirely, no matter how technically sound the analysis behind it is. Before touching a device, an investigator needs to know who authorized the collection and why.
Authority to collect generally comes from one of a few sources: informed consent from the device owner, a legal hold issued once litigation is anticipated, a court order or warrant, or standing corporate policy that employees have already agreed to (commonly covered by an acceptable use or monitoring policy).
| Investigation Type | Typical Legal Basis | Example |
|---|---|---|
| Internal / HR investigation | Employment agreement, acceptable use policy, employer-owned device | Suspected policy violation on a company laptop |
| Law enforcement investigation | Warrant or other judicial authorization | Seizure of a device as part of a criminal case |
| Civil litigation / eDiscovery | Legal hold, discovery request between parties | Preserving email and file activity ahead of a lawsuit |
| Regulatory investigation | Statutory reporting or audit authority of a regulator | Regulator-mandated review after a breach disclosure |
Whatever the basis, evidence only stays usable later if four things hold: the collector had proper authority, custody was unbroken from collection to presentation, the methodology was sound and repeatable, and another qualified examiner could reproduce the same result from the same evidence. Privacy and regulatory factors matter too, data residency rules, employee privacy expectations, and what a policy actually permits to be searched all shape what an investigator is allowed to touch before any technical work starts.
Order of Volatility
Not all evidence decays at the same rate. Some data disappears the moment power is lost, other data can sit untouched on a disk for years. Collection has to move from the most volatile sources to the least, or the fast-decaying evidence is gone before anyone gets to it.
This ordering comes from RFC 3227, Guidelines for Evidence Collection and Archiving (February 2002), which tells collectors to work from the volatile to the less volatile in this sequence: registers and cache; routing table, ARP cache, process table, kernel statistics and memory; temporary file systems; disk; remote logging and monitoring data relevant to the system; physical configuration and network topology; archival media. The flow above splits system memory and swap out as their own steps, since in practice they are captured by separate tools, but the ranking is the RFC's.
Chain of Custody
Chain of custody is a continuous, documented record of who possessed a piece of evidence, when, and what they did with it. A gap in that record is often enough for opposing counsel or an auditor to question whether the evidence was tampered with, even if it wasn't.
| Field | Purpose |
|---|---|
| Item description / identifier | Uniquely identifies the exact piece of evidence (serial number, case ID, label) |
| Collected by (name) | Ties the initial acquisition to an accountable individual |
| Date / time of each transfer | Establishes a timeline with no unexplained gaps |
| From / to (custodian) | Shows exactly who held the evidence at every point |
| Purpose of transfer | Explains why possession changed hands (analysis, storage, court) |
| Location stored | Confirms the evidence was kept somewhere secure and access-controlled |
| Hash value at each step | Proves the evidence itself was never altered |
The Forensic Investigation Process
Most forensic work follows the same high-level lifecycle, regardless of which branch is involved. Each stage exists to protect the integrity of the stage before it.
The rest of this module walks through each branch this process is applied to:
- Disk and File System Forensics: recovering deleted files, parsing file system metadata, and reading slack space.
- Windows Artifact Forensics: registry hives, event logs, prefetch, and other OS-level evidence.
- Memory Forensics: capturing and analyzing RAM for processes, injected code, and live network state.
- Timeline Analysis: correlating timestamps across sources into a single sequence of events.
- Network Forensics: packet captures, flow data, and log-based reconstruction of network activity.
- Mobile and Cloud Forensics: device backups, app data, and cloud control-plane evidence.
- Anti-Forensics and Reporting: recognizing evidence tampering and writing findings up for presentation.
Key Takeaways
- Digital forensics splits into distinct branches, disk, memory, network, mobile, and cloud, each recovering different evidence and triggered by different scenarios.
- Evidence only remains usable later if it was collected under proper legal authority, with unbroken custody, sound methodology, and reproducible results.
- Collection must follow order of volatility, most volatile sources (registers, memory) first, most durable (backups) last, or fast-decaying evidence is lost.
- Chain of custody is a continuous documented record of who held evidence, when, and what they did with it, verified at each step by hashing.
- The forensic process runs through six stages: identification, preservation, collection, examination, analysis, and presentation.
- This module is the technical evidence-handling skillset that Incident Response investigations draw on once proof, not just triage, is required.
Knowledge Check
Click an answer to reveal the explanation.
Following order of volatility, which of these should generally be captured first on a live, running system?
A chain of custody log is missing the hash value recorded at the point of collection. What does this gap put at risk?
Which stage of the forensic investigation process comes immediately after preservation?