Acquisition is the process of getting evidence off a device — a phone, a laptop, a server, a cloud tenant — in a way that can be relied on later. It sounds procedural. It is where most cases are quietly won or lost, because the decisions taken between the moment the device is seized and the moment the image is verified determine what is available for analysis, and what is admissible in court.
What a defensible acquisition includes
- 01Contemporaneous documentation. Make, model, serial or IMEI, physical condition, power state on arrival, seals intact yes/no, examiner name and time — recorded before the device is touched further.
- 02Network isolation. Faraday bag, airplane mode with Wi-Fi and Bluetooth disabled, or a physically air-gapped acquisition rig — chosen for the device type and recorded in the note.
- 03Write protection. A hardware write-blocker for storage media, a supported acquisition agent for a mobile device, a read-only mount for cloud sources. The device is treated as evidence, not as a working system.
- 04Method selection. The lightest method that reaches the artefacts required by the pleaded issue — see our piece on logical vs physical extraction for the ladder.
- 05Hash-verified imaging. SHA-256 (and, on legacy matters, MD5) computed at acquisition, recorded on the exhibit paperwork, and re-verified on every subsequent copy. The master image is stored, sealed and untouched; all analysis runs on working copies.
- 06Chain of custody. A single sheet, kept from seizure to disposal, recording every person who has held the exhibit, the date, and the purpose. This is the document opposing counsel will ask for first.
What proper acquisition documentation records
| Field | Why it matters |
|---|---|
| Device identifiers (make, model, IMEI, serial) | Ties the image to a physically identifiable exhibit |
| State on arrival (BFU/AFU, powered on/off, locked/unlocked) | Determines what methods are available and what data is in reach |
| Isolation method and time | Rebuts any suggestion of remote wipe or post-seizure change |
| Acquisition method and tool version | Allows the methodology to be tested against known limitations of the tool |
| SHA-256 hash of image and every copy | Proves the working copy is identical to what was acquired |
| Examiner name and signature | Establishes the individual who will attend to defend the acquisition |
What goes wrong when acquisition is done casually
- Devices arrive already unlocked and browsed by the client or their IT team — every message app has been opened, timestamps updated, and the pristine state lost.
- "Working copies" are taken from earlier working copies, so hashes cannot be tied back to the original acquisition.
- Acquisition is performed on the live device rather than on an image, and the examiner's own tooling has written to the exhibit.
- An in-house IT team makes an iTunes or vendor backup and calls it a forensic image — it is not hash-verified, is not complete, and cannot be defended as one.
- The device is powered on to "just check" it, moving a BFU device into AFU and burning one-shot exploit windows that would otherwise have supported a deeper extraction.
Any one of these failings is enough to unpick the evidence in cross-examination. The good news is that all of them are avoided by the same discipline: treat the device as evidence from the first minute, and let an examiner acquire it before anyone else touches it.
Cloud and remote acquisitions
Not all acquisitions involve a physical device on a bench. Cloud tenants (Microsoft 365, Google Workspace, iCloud, AWS), SaaS platforms and social-media accounts are increasingly acquired remotely under written authority, using vendor APIs and specialist tooling. The principles are the same: authenticated access under a documented mandate, immutable export in a native format, hash verification of the export, and a contemporaneous note of what was pulled, when, and by whom.
Frequently asked questions
A logical mobile acquisition is often complete within a working day. A full file system or physical acquisition on a modern device can take several days end-to-end. A single-disk laptop image is typically 4–12 hours; a server or a full cloud tenant can take considerably longer.
No. The correct depth is dictated by the pleaded issues and by what the device model and firmware actually support — over-specifying wastes budget on questions the case does not turn on.
Chip-off or JTAG is available as a last resort on unbootable or physically damaged devices. It is destructive on chip-off and specialist on JTAG; both are reserved for cases where less invasive methods are not available.
Yes, where the device cannot leave site. A field acquisition uses the same tools and the same documentation as a laboratory acquisition — the only difference is the location and, occasionally, the availability of specialist rigs.
It is sealed, tagged and returned to the instructing party or held under retention agreement, depending on the matter. The examination is then conducted exclusively on the image, so the original can be re-acquired if a later challenge requires it.
