
Digital Evidence Acquisition & Analysis Protocol
Acquire, preserve, and analyze digital evidence with forensic integrity and legal admissibility
What You Can Do
You can manage the complete digital evidence lifecycle—from initial device assessment through expert testimony preparation. This skill ensures forensic soundness, legal admissibility, and compliance with evidentiary standards (Daubert, FRE 702) while documenting proper chain of custody procedures. You'll generate forensically valid reports that clearly explain methodologies to non-technical audiences and prepare materials that defend your findings under cross-examination.
Features
Classify evidence items by type, operating system, and acquisition requirements to select appropriate forensic tools
Document acquisition procedures (bit-for-bit copying, write-blocking, hash verification) that demonstrate legal admissibility
Create detailed evidence logs tracking possession, handling, and analysis from seizure through disposition
Systematically search, extract, and correlate recovered data (files, artifacts, timelines) relevant to investigation objectives
Write court-ready reports that explain forensic methodologies, findings, and conclusions in language accessible to judges and juries
Develop materials addressing common defense challenges, Daubert challenges, and cross-examination scenarios
Track relationships between multiple evidence items and data sources to build coherent investigative narratives
Example Output
Forensic Imaging Report Excerpt:
- Device: Apple iPhone 12 Pro (Evidence #2024-001)
- Acquisition Method: Logical extraction via Cellebrite UFED (write-blocked environment)
- Hash Value (MD5): a1b2c3d4e5f6... [Original/Acquired match verified]
- Chain of Custody: 4 documented transfers, final analyzed by SA Rodriguez on 2024-01-15
- Key Findings: 47 deleted SMS messages recovered from WhatsApp database; timeline correlation with incident window; metadata inconsistencies noted
Analysis Summary Chart:
✓ Boot artifacts analyzed (system logs, prefetch files)
✓ Browser history cross-referenced with network logs
✓ Deleted file recovery completed and classified
✓ Timeline reconstruction: suspect device active 11:34 PM–12:47 AM (incident window)
✓ Methodologies documented for Daubert compliance
What's Included
- SKILL.md: Complete digital evidence protocol with workflows for acquisition, analysis, documentation, and reporting
- Evidence Acquisition Checklist: Step-by-step procedure covering device seizure, write-blocking, imaging, and hash verification
- Chain of Custody Template: Standardized form tracking evidence possession, handling, and analysis from initial seizure through final disposition
- Expert Report Framework: Structured outline for forensic reports addressing methodology, findings, limitations, and conclusions for legal admissibility
- Testimony Preparation Worksheet: Guidance for addressing Daubert challenges, cross-examination scenarios, and expert qualification questions
Who It's For
- Digital forensic scientists conducting criminal and civil investigations
- Law enforcement investigators managing computer and device evidence
- Cybercrime specialists analyzing seized electronics for financial or identity crimes
- Corporate security teams handling internal digital investigations with legal implications
- Legal professionals (prosecutors, defense attorneys) preparing digital evidence for trial
Best For
- Forensic imaging of computers, phones, tablets, and storage media
- Chain of custody documentation and evidence preservation
- Expert report generation for court admissibility
- Analysis of recovered data (deleted files, communication history, artifacts)
- Testimony preparation defending forensic methodologies and findings







