DIGITAL EVIDENCE FORENSIC REPORT
CASE INFORMATION:
Agency Case #: Originating Agency Case
#:
Date/Time Report Completed: Date/Time Incident
Occurred:
Type of Report: Initial
SUMMARY:
EVIDENCE SUBMITTED:
Item #
SOFTWARE UTILIZED
Item #
FORENSIC EXAMINATION OF EVIDENCE
ITEM #1
FORENSIC IMAGING
After obtaining the hash value(s) of the original media, a forensic image was created. The forensic
image was placed on a:
Government owned, forensically wiped hard drive
Government owned, forensically wiped Storage Area Network (SAN)
Page 1 of 3
The forensic imaging software utilized in this process creates an imaging report, detailing the hash
value(s) of the newly created forensic image. The hash value(s) of the forensic image was compared
to the original hash value obtained prior to imaging the device. The hash value(s) of the forensic
image:
Matched exactly the hash value(s) of the original media.
Did not match the original hash value(s) of the media. If checked, provide explanation below.
VIRUS AND MALWARE
The original media was scanned for malware. Prior to the scan, all malware definitions were updated.
The results were:
No malware detected.
Malware detected. If checked, identify and report on malware located below.
BIOS EXAMINATION
Once the hard drive was removed, the computer was turned on and the BIOS (Basic Input/Output
System) checked. The following was found:
The date and time were accurate.
The date was accurate, but the time was inaccurate. List time offset from correct time:
The time was accurate, but the date was inaccurate. List date offset from correct date:
Forensic computer was adjusted to compensate for any time differences.
What was used as a time reference:
Cellular phone set by network.
Other:
FORENSIC EXAMINATION OF FILES
DISPOSITION
EVIDENCE DISPOSITION
FORENSIC EXAMINER’S CONCLUSION
ATTACHMENTS
DIGITAL FORENSIC EXAMINER:
EDMAR J. SAMORTIN