Digital Chain of Custody: What It Is and Why Your Report Needs It

By Juan Jesús Merino Carretero, chartered computer engineer no. 89 (CPIIEX) chain of custody · computer forensics · methodology

Digital Chain of Custody: What It Is and Why Your Report Needs It

The digital chain of custody is the procedure that guarantees that a piece of digital evidence reaches the courtroom exactly as it was when collected. Without it, any expert report is vulnerable to challenge: the opponent can argue that the evidence has been manipulated, altered or replaced at some point in the process. For lawyers and companies, understanding how the chain of custody is documented is understanding why some expert reports hold up and others do not.

Technical and procedural definition

The chain of custody is the set of documented actions that record the handling of a piece of digital evidence from its collection to its presentation in court. Every step is traced: who had access to the evidence, when, where and for what purpose. The chain of custody rests on two pillars:

  1. Paper documentation (records, logs).
  2. Technical documentation (cryptographic hashes, forensic logs, integrity marks).

If at any point the chain is broken —for example, if the device is left in a drawer without a record, if someone powers it on without protocol, if it is connected to a network— procedural integrity is compromised.

How a solid chain of custody is built

Step 1: Collection record

The owner of the evidence (phone, computer, drive) hands it to the expert through a record signed by both parties that contains:

  • Identification of the person handing it over and of the expert.
  • Description of the device (make, model, serial number, IMEI).
  • Condition in which it is handed over (on/off, battery, visible damage).
  • Date, time and place.
  • Purpose of the expert work.

Step 2: Write blocking

Before any analysis, the expert connects the device to a hardware write blocker or applies equivalent software protocols. This guarantees that not a single byte is written to the original device, which would preserve procedural integrity even if something were discovered later that made it necessary to review the original.

Step 3: Bit-for-bit cloning

A forensic image of the medium is made: an identical byte-for-byte copy, not a “file copy”. The most widely used tools are:

  • Drives: FTK Imager, dd, Guymager, EnCase Imager.
  • Phones: Cellebrite UFED, Magnet AXIOM, Oxygen Forensic Suite.
  • Cloud: extraction via API with the account holder’s authorization.

Step 4: Calculating MD5 and SHA-256 hashes

Each hash is a cryptographic fingerprint of the medium: a unique string of characters that identifies exactly that evidence. If someone modifies a single bit, the hash changes. Two different hashes (MD5 and SHA-256) are calculated for redundancy — an attacker cannot alter the content and keep both hashes intact at the same time.

Example of a SHA-256 hash:

9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08

That hash is included in the report and in the record of the forensic image. If the opposing party doubts the integrity, it is enough to recalculate the hash on the image and compare.

Step 5: Secure storage

The original evidence and the forensic image are kept on encrypted media in facilities with access control. Any later access is documented. The working copy (on which the analysis is carried out) is made from the image, not from the original.

Step 6: Analysis on the copy

All forensic analysis (file searches, recovery of deleted files, log examination) is done on the copy, not on the original. Every tool used leaves an auditable log.

Step 7: Return and completion record

When the expert work is finished, the original device is returned to the client with a signed return record documenting the condition in which it is returned and the final hashes (which must match the initial ones).

What happens if the chain of custody fails

These are the real-life scenarios that invalidate or weaken a report:

Case 1: the client “opens and looks” at the computer before bringing it in

Every time a computer is powered on, hundreds of system files are modified (logs, access dates, event records). The expert can no longer certify the original state. The opposing party can challenge: how do I know that what is in the report wasn’t modified by the client when they started the computer?

Case 2: a “file copy” is made, not a bit-for-bit clone

A file copy does not capture unallocated space, where deleted files are. If the case depends on recovering deleted data, the expert will no longer be able to do so. And if it is submitted as evidence, a challenge for technical insufficiency is unavoidable.

Case 3: hashes are not calculated

Without hashes, there is no way to prove that the forensic image is identical to the original. The opposing defense can argue manipulation.

Case 4: the device is held in custody without documentation

If between collection and the expert work the device sits in a drawer in the lawyer’s office for weeks, with no custody record or documentation, there is a gap in the chain. A typical cause of challenge.

Case 5: multiple experts without documented transfer

Sometimes an initial technician is involved and then an expert. If the transfer between the two is not documented with a record and hashes, the chain is broken.

Hashes: the heart of integrity

Hashes are one-way mathematical functions: given a file, they produce a fixed-length string; given the hash, the file cannot be recovered. Two different hashes are used for safety:

  • MD5 (128 bits): fast, widely supported.
  • SHA-256 (256 bits): cryptographically stronger, recommended for evidence.

These hashes are calculated at four points in the chain:

  1. On the original device when collecting it (when technically possible).
  2. On the forensic image when creating it.
  3. On the image when starting the analysis (integrity check).
  4. On the image when finishing the analysis (confirmation that it has not changed).

Chain of custody in cloud and SaaS

When the evidence is in the cloud (Google Workspace, Microsoft 365, Dropbox), the chain is adapted:

  • Access with the credentials of the legitimate account holder.
  • Export with a timestamp from the cloud provider.
  • Hashes on the downloaded exports.
  • Documentation of the version and date of extraction (because the cloud may delete older versions).

Forenlab carries out extractions with chain of custody both on physical devices and in cloud and SaaS environments.

Frequently asked questions

How much does it cost to document the chain of custody?

It is included in the price of the expert report. It is not a separate service. If an expert offers to “make the report cheaper by skipping the chain of custody”, walk away.

Do the police apply a chain of custody?

Yes. Spain’s state security forces apply established forensic protocols (Guardia Civil GDT, Policía Nacional UDEF). If a party-appointed expert gets involved afterwards, the transfer is documented.

Can I collect the evidence myself and hand it to the expert?

Yes, with a signed voluntary transfer record. What matters is not to power on, modify or tamper with the device between the incident and the handover to the expert.

Is the same chain of custody applied in preventive engagements (audits)?

Yes. Even if the purpose is not judicial, maintaining the chain means the evidence can be used in court if a complaint is eventually filed.

What if I lose the original record?

The expert always keeps a signed copy. Ask for it.

Conclusion

The digital chain of custody is the difference between a solid report and a challengeable one. Any serious expert documents it as part of the work, at no extra cost, and incorporates it into the expert report. At Forenlab every engagement includes signed records, MD5 and SHA-256 hashes, certified forensic tools and full traceability. Contact us and we will explain how we would apply chain of custody in your specific case.