EvidenceDemo laboratory

Learn digital evidence fundamentals

HomeLearn digital evidence fundamentals

Start with the distinction

A screenshot preserves appearance. Evidence needs documented context.

The story explains the source, collection time, method, integrity and limitations of what was observed.

SCREENSHOT

A useful visual record

  • Shows the pixels visible at one moment
  • Can be cropped, edited or separated from its source
  • Usually omits collection method and technical context
  • May still be useful when its limitations are understood

PRESERVED EVIDENCE

A reviewable collection

  • Connects content to a source and collection time
  • Preserves relevant metadata and contextual information
  • Supports integrity checks and a documented audit trail
  • Can be assessed and reproduced by another reviewer

Core concepts

The vocabulary of a stronger capture

01

Source context

The URL, page title, publisher, author and surrounding material that explain where an item appeared.

Can the captured statement be tied to a specific source?

02

Provenance

Information describing the origin of an artifact and the sequence by which it reached the reviewer.

Who collected it, from where and by which process?

03

Integrity

Confidence that preserved material has not changed unnoticed after collection.

Can later modifications be detected?

04

Hash

A deterministic fingerprint used to compare data. Matching hashes support an integrity check.

Does the reviewed file match the preserved artifact?

05

Timestamp

A recorded time associated with collection or another event, interpreted together with its source and timezone.

Which event does this time actually represent?

06

Audit trail

A chronological record of collection, processing, access and verification actions.

Can another reviewer follow what happened?

Capture checklist

Ask before, during and after collection

A repeatable checklist reduces ambiguity and helps another person understand the limits of the result.

Practice with a scenario
1

Define the claim

Write down the exact fact, statement, price, version or relationship the exercise concerns.

2

Set the scope

Decide whether one page is enough or whether links, navigation and surrounding context matter.

3

Preserve identifiers

Record URLs, titles, authors, timestamps, reference numbers and visible version information.

4

Document the method

Explain the tool, collection steps and any transformations made after capture.

5

State limitations

Separate what was observed from what the capture cannot independently establish.

Ready to apply the concepts?

Start with a beginner notice, then progress to corrections and versioned policies.

Browse exercises