Francesco ZinghinìParty-appointed technical expertise

The forensic report: how I work

A forensic report is worth exactly as much as its repeatability. If another expert, starting from the same data and reading the report, does not reach the same result, that report is not evidence: it is an opinion.

Identification: what is actually needed

The first step is not a technical one. Before touching a device one has to know which fact must be proved and which rule makes it relevant, because that is what determines what to acquire. Acquiring everything is expensive, slow and sometimes counter-productive: a full extraction from a smartphone brings with it the private lives of third parties who have nothing to do with the case, and raises proportionality problems that a narrower scope would have avoided.

This stage also establishes what is still recoverable. That question has an expiry date: cloud provider logs, carrier records and rotating backups have limited retention windows, and whatever is not frozen in time simply ceases to exist.

Acquisition and integrity

There is a single principle: one never works on the original. A copy is produced that reproduces the medium bit for bit, a hash value is computed over it, and from that moment any later check can demonstrate that the material examined is identical to the material acquired.

The hash is why the copy holds. It is the output of a function that, applied to a sequence of bytes, produces a fixed-length value: change a single bit and the value changes unpredictably. It conceals nothing; it fixes a moment — this was the content, at that time. For the functions still regarded as sound today — the SHA-2 family — there is no practical technique for constructing two different contents with the same value; for MD5 and SHA-1 there is. Those remain reasonable as additional values, for continuity with existing documentation, but not on their own.

Where the original cannot be copied — an online service, a mailbox reachable only through a browser, a page that will not exist tomorrow — the form of the acquisition changes but the principle does not: the session is documented, the technical identifiers of the connection are recorded, and the result is fixed with the same integrity check.

Forensic acquisition in detail →

Chain of custody

The chain of custody is the documented account of where the material has been and who handled it, from seizure or delivery through to examination. It is not paperwork: it is what allows the simplest and most lethal question in cross-examination to be answered — how can you rule out that someone altered it in the meantime?

In practice that means records stating date, time, place, persons present, serial numbers, hash values computed on delivery and recomputed on opening, and sealed, identified media. Every handover is a link: if one is missing, the whole chain is open to attack.

Analysis

Analysis is carried out on the copy, with tools whose name and version I state, and with steps described so that they can be retraced. Where I use a script of my own, I append it: a tool nobody can inspect is not verifiable, and what cannot be verified counts for little in court.

The rule I hold myself to is not to make the data say more than it says. A file recorded as modified at 3:14 tells you that the operating system recorded that modification on that volume, with the clock that system had at that moment. It does not tell you who was at the keyboard, nor that the clock was correct, nor that the document was written at that instant. The distance between those statements is where cases are won and lost.

The report

The report is written to be read by a lawyer, not by a computer scientist. It sets out the question, the material examined with its identifiers and hash values, the method and tools used, the results, and the conclusions.

In the conclusions I keep three levels apart and name them: what is established (the data is this and anyone can re-verify it), what is a technical assessment (the data is consistent with this reconstruction and inconsistent with that one, to this degree of confidence), and what remains unknown (not determinable from the available data). A report that blurs the three falls apart under cross-examination.

What a forensic report cannot do

Worth stating before starting, because it prevents expectations that become expensive disappointments.

  • It does not attribute an act to a person. The data connects an act to an account, a device, a network address. Getting from «that device» to «that person» is an evidential inference for the court; the report can only supply material for it.
  • It does not recover what has been overwritten. Deleted data is often recoverable; overwritten data is not, and no tool changes that.
  • It does not defeat encryption. Without the key or the holder's cooperation, properly encrypted content stays inaccessible.
  • It does not certify that content is true. One can show that a message was sent from a given account at a given time; whether what it says is true is another matter entirely.

And if the analysis goes against the instructing party? I say so before filing. A report written to please reveals itself in the hearing, when nothing can be done, and takes the credibility of the whole defence down with it. An unfavourable result known in time is, by contrast, useful information: it is what allows another route to be taken, or a settlement to be reached.

What it costs

It depends on identifiable factors — how many devices and in what state, the scope of the engagement, the analysis required beyond acquisition, the urgency — and any serious matter is priced on a written quote stating what will be acquired, how, and what will be delivered. The cost drivers, the market's orders of magnitude and how to read a quote are covered in a dedicated piece: how much a digital forensics report costs.

Do you have a matter under way?

Tell me what happened and what you need to prove. In a first reply I will tell you whether there is a technical route, what data is needed and how long it takes — before any commitment.

Request an assessment