Evidence integrity
Confidence that fictional evidence remains complete, traceable, protected from undocumented change, and consistent with its preserved source and handling record.
Learn how an authorized defender protects fictional originals, verifies copies, distinguishes evidence types, records every transfer and access event, preserves source lineage, investigates integrity exceptions, and explains exactly what a hash can and cannot prove.
Lesson Progress
High School Intermediate • I12: Digital Forensics Basics • Lesson 3 of 8
Readiness Check
0/5 ready
Professional Hook
The fictional Northbridge case now contains metadata, identity, process, cloud, application, deployment, support, and source-health records. Several preserved copies and working copies must move between fictional owners, custodians, analysts, and reviewers. One failed working-copy verification appears during the process. The team must determine whether the problem came from an incomplete transfer, a wrong version, a packaging change, corruption, or a real content difference without hiding the mismatch or overstating what it proves.
Weak handling
Reuse one filename and one identifier for every copy, work directly on originals, delete failed copies, and treat a hash mismatch as proof of tampering.
Professional handling
Preserve originals, assign unique identifiers, verify at control points, record every handler and purpose, quarantine exceptions, create new verified copies, and maintain complete lineage.
Objective 1
Explain how fictional evidence integrity supports trust, reproducibility, review, transfer, analysis, reporting, and closure.
Objective 2
Distinguish original evidence, preserved copies, verified working copies, exports, screenshots, notes, and derived evidence while maintaining clear source lineage.
Objective 3
Use fictional cryptographic hash concepts appropriately as integrity checks without claiming that a matching hash proves ownership, intent, completeness, or authenticity by itself.
Objective 4
Create a complete fictional chain-of-custody record containing evidence identifiers, owners, transfers, access events, purposes, timestamps, integrity checks, conditions, and exceptions.
Objective 5
Recognize and document integrity risks involving renaming, conversion, extraction, decompression, metadata changes, unsupported tools, incomplete transfers, missing handlers, and unclear custody.
Why This Matters
A fictional hash result can help verify that two compared data objects are identical, but trustworthy handling also requires identifiers, source ownership, authorization, preservation, verification method, transfers, access history, storage, working copies, derived-artifact lineage, limitations, exceptions, review, and disposition. A complete record allows another reviewer to understand where the evidence came from and how each conclusion was produced.
Core Concept
Identity
Which exact fictional evidence object, source, owner, time window, type, version, and case question are being handled?
Integrity
Which fictional method verified the object before and after collection, transfer, copying, analysis, storage, or archive?
Custody
Who controlled, transferred, stored, accessed, reviewed, or approved the fictional evidence, when, why, and under which conditions?
Lineage
Which fictional originals produced each copy, filter, screenshot, note, timeline, exhibit, finding, and report statement?
Key Vocabulary
Confidence that fictional evidence remains complete, traceable, protected from undocumented change, and consistent with its preserved source and handling record.
A fixed-length fictional integrity result produced from digital data. Matching values can support that two compared copies are identical under the chosen method.
The fictional process of comparing expected and observed integrity information before and after transfer, copying, analysis, or storage.
The fictional first preserved form of an approved record or acquisition that should remain protected from analysis changes.
A fictional protected copy created from an approved source and retained as a stable reference.
A fictional verified copy used for authorized analysis so the original or preserved reference remains unchanged.
A fictional filtered export, screenshot, timeline, table, note, chart, extracted file, or report item created from earlier evidence.
The fictional relationship connecting every derived record back to the original or preserved source that produced it.
The fictional chronological record of who possessed, transferred, accessed, stored, reviewed, or modified the handling state of evidence and why.
The fictional person or role responsible for preserving, controlling, transferring, and documenting evidence according to the case plan.
A fictional documented change in evidence possession, storage location, control, or access responsibility.
A fictional documented instance in which evidence was opened, copied, verified, analyzed, exported, or reviewed under an approved purpose.
A fictional condition such as a mismatch, missing handler, altered metadata, incomplete copy, failed verification, or unclear transfer that requires investigation and escalation.
A fictional planned moment when evidence integrity is checked, such as after collection, transfer, storage, working-copy creation, or final archival.
The fictional final approved action for evidence, such as retained, archived, returned, transferred, or securely deleted under policy.
Hash Concepts
When the same approved method produces the same value for two compared files, the result can support that the file contents are identical at the time of comparison.
Can support
Copy verification, transfer verification, working-copy verification, archive checks, and duplicate-content comparison.
Does not prove
Who created the file, who intended an action, whether the source is complete, whether the file is authorized, or whether every surrounding record is trustworthy.
A mismatch shows that the compared data is not identical under the chosen method, but it does not automatically prove malicious alteration.
Can support
The need to investigate copy method, source version, transfer completeness, decompression, conversion, metadata inclusion, corruption, or actual content change.
Does not prove
Automatic proof of tampering, guilt, breach, or intentional evidence destruction.
A fictional hash should be connected to the exact evidence object, method, tool, time, handler, and version being verified.
Can support
Reproducibility and accurate comparison between the correct files or images.
Does not prove
Comparing unrelated exports, differently packaged folders, converted files, or extracted data without documenting the transformation.
A fictional value alone does not explain where the evidence came from, who possessed it, how it was transferred, or which copy was analyzed.
Can support
Integrity checks when combined with identifiers, lineage, custody, storage, access, and transfer records.
Does not prove
A complete chain of custody by itself.
A fictional timeline, screenshot, table, or filtered export should be identified separately while preserving its parent-source references.
Can support
Clear distinction between originals and analyst-created artifacts.
Does not prove
Replacing original evidence with a screenshot or summary.
Fictional evidence should be checked at meaningful control points rather than only once during collection.
Can support
Detection of transfer errors, storage changes, incomplete copying, wrong-file selection, and undocumented modification.
Does not prove
A guarantee that no future handling problem can occur.
Chain-of-Custody Fields
Purpose
Provides a unique fictional reference for the exact original, preserved copy, working copy, export, screenshot, note, or derived artifact.
Fictional example
NRA-E-003-ORIG, NRA-E-003-WORK-01, or NRA-D-014-TIMELINE.
Risk if missing
Reusing one identifier for several objects makes transfers, access, and findings ambiguous.
Purpose
Explains what the fictional evidence is, which source or subject it covers, and the relevant time or case boundary.
Fictional example
Supplied process snapshot for the archive-export worker captured at 09:24.
Risk if missing
A vague description such as log file can cause the wrong evidence to be reviewed.
Purpose
Records the fictional system, export process, custodian, data owner, or provider responsible for the evidence.
Fictional example
Northbridge Archive Platform, supplied by the fictional platform custodian.
Risk if missing
Unknown ownership weakens authorization, provenance, and transfer accountability.
Purpose
Records when the fictional evidence was created, exported, received, or preserved, including time zone and source timing limitations.
Fictional example
Received 2026-07-21 09:31 UTC-04:00; source clock reported current.
Risk if missing
Missing time-zone or source-health information can distort chronology.
Purpose
Records the fictional verification method, expected result, observed result, tool or process, and comparison time.
Fictional example
Preserved-copy verification matched the original supplied package.
Risk if missing
A value without object identity, method, or comparison context is difficult to reproduce.
Purpose
Documents the fictional approved location, access restriction, encryption or protection state, backup, retention, and monitoring.
Fictional example
Restricted evidence repository; read access limited to incident lead, evidence custodian, and assigned analyst.
Risk if missing
Uncontrolled storage creates exposure, loss, and undocumented access risk.
Purpose
Records every fictional change in possession, location, custody, or control with sender, receiver, time, purpose, condition, and verification.
Fictional example
Custodian transferred working copy to assigned analyst for metadata review; verification passed.
Risk if missing
A missing handler creates an unexplained custody gap.
Purpose
Records who opened, copied, verified, filtered, exported, reviewed, or used the fictional evidence and why.
Fictional example
Analyst reviewed the verified working copy to compare paths, hashes, and timestamps.
Risk if missing
Unlogged access prevents reviewers from understanding potential changes or exposure.
Purpose
Connects fictional screenshots, notes, timelines, tables, findings, and reports to the exact parent evidence records.
Fictional example
Timeline event T-07 derived from NRA-E-002, NRA-E-003, and NRA-E-005.
Risk if missing
Unsupported summaries can become detached from their original evidence.
Purpose
Records fictional mismatches, damage, incomplete transfer, out-of-scope material, restricted evidence, retention, return, archive, or deletion decisions.
Fictional example
Working copy mismatch quarantined; new copy created and verified; failed copy retained as exception evidence.
Risk if missing
Deleting or hiding exceptions can make the custody record inaccurate.
Evidence Types
The first fictional approved record received or preserved for the case.
A fictional protected copy retained as a stable comparison point when the original source must remain separately controlled.
A fictional verified copy used for approved sorting, filtering, indexing, annotation, or tool review.
A fictional subset created from a working copy to focus on approved fields, identities, events, or time windows.
A fictional visual representation created for review, teaching, or reporting.
A fictional record of observations, questions, methods, hypotheses, decisions, and limitations.
A fictional derived chronology combining events from several sources.
A fictional approved artifact selected to support a report finding or limitation.
Defensive Workflow
Create the fictional case identifier, evidence identifier, description, source, owner, subject, time window, authorization reference, and evidence type.
Output: Evidence register entry.
Protect the fictional original or first supplied form, record packaging and source context, restrict access, and avoid analysis changes.
Output: Original-preservation record.
Record the fictional verification method, expected and observed result, handler, time, tool or process, and any mismatch or limitation.
Output: Integrity verification record.
Copy from the preserved source using the approved method, assign a new identifier, verify the copy, and document its parent lineage.
Output: Verified working-copy record.
Document every fictional sender, receiver, custodian, location, time, purpose, condition, verification, and authorized access event.
Output: Chain-of-custody and access history.
Assign identifiers to fictional screenshots, filters, timelines, tables, notes, and exhibits while preserving parent records and transformation details.
Output: Derived-evidence lineage map.
Quarantine fictional mismatches, incomplete transfers, damaged files, unknown handlers, wrong identifiers, altered metadata, or unsupported formats without hiding the problem.
Output: Integrity exception and corrective action record.
Confirm fictional completeness, verification, custody, access, lineage, exceptions, owner approval, retention, disposition, and portfolio-safety requirements.
Output: Evidence-handling completion review.
Fake Dashboard
Training dashboard for fictional evidence handling only.
Original evidence records
6
Six fictional original or first-preserved records are registered and protected.
Verified working copies
5
Five working copies passed comparison before analysis.
Open integrity exceptions
1
One failed copy is quarantined while a new verified copy and corrective record are completed.
Fake SOC Alert
Source: Fake Evidence Integrity Console • Time: 09:52 AM
Fake Log Panel
09:06 RECEIVE evidence='NRA-E-002-ORIG' sender='Platform-Custodian' 09:07 VERIFY evidence='NRA-E-002-ORIG' result='pass' 09:11 PRESERVE evidence='NRA-E-002-PRES-01' parent='NRA-E-002-ORIG' 09:15 COPY evidence='NRA-E-002-WORK-01' parent='NRA-E-002-PRES-01' 09:16 VERIFY evidence='NRA-E-002-WORK-01' result='pass' 09:23 RECEIVE evidence='NRA-E-003-ORIG' source='Process-Snapshot' 09:34 RECEIVE evidence='NRA-E-004-ORIG' source='Identity-Export' 09:41 RECEIVE evidence='NRA-E-005-ORIG' source='Cloud-Audit' 09:47 COPY evidence='NRA-E-005-WORK-01' parent='NRA-E-005-ORIG' 09:52 VERIFY evidence='NRA-E-005-WORK-01' result='fail' 09:53 QUARANTINE evidence='NRA-E-005-WORK-01' exception='INT-01' 09:58 REVIEW transfer='incomplete_package' source_version='confirmed' 10:01 COPY evidence='NRA-E-005-WORK-02' parent='NRA-E-005-ORIG' 10:02 VERIFY evidence='NRA-E-005-WORK-02' result='pass' 10:18 DERIVE evidence='NRA-D-014' type='timeline_v2' 10:45 REVIEW custody='complete' exceptions='documented'
Training note: this is fake data for defensive analysis practice only.
Fictional Evidence Register
Source
Fictional archive owner
Integrity
Verified upon receipt; no later change recorded.
Custody
Received by evidence custodian and stored in the restricted case repository.
Lineage
Parent of intake summary NRA-D-001.
Source
Fictional archive platform
Integrity
Initial and post-transfer verification matched.
Custody
Transferred from platform custodian to evidence custodian.
Lineage
Parent of working copy NRA-E-002-WORK-01 and exhibit NRA-D-011.
Source
Derived from NRA-E-002-ORIG
Integrity
Verified against preserved source before analysis.
Custody
Assigned to fictional forensic analyst for path, timestamp, and hash comparison.
Lineage
Parent of filtered table NRA-D-006.
Source
Fictional endpoint custodian
Integrity
Verified at receipt; capture-method limitation documented.
Custody
Transferred through the evidence custodian to restricted storage.
Lineage
Parent of process map NRA-D-008.
Source
Fictional identity platform
Integrity
Verification passed after export transfer.
Custody
Received from identity owner with approved time-window statement.
Lineage
Parent of identity-event subset NRA-D-009.
Source
Fictional cloud platform
Integrity
Verification passed; retention and event-coverage limitations recorded.
Custody
Vendor export transferred to platform custodian, then evidence custodian.
Lineage
Parent of sharing-check table NRA-D-010.
Source
Fictional archive application
Integrity
Verification passed after delayed delivery; completeness review completed.
Custody
Application owner transferred export after source repair.
Lineage
Parent of timeline version 2 NRA-D-014.
Source
Derived from NRA-E-002, NRA-E-003, NRA-E-004, NRA-E-005, and NRA-E-006
Integrity
Derived artifact identifier and parent-source references verified.
Custody
Created and reviewed within the fictional forensic workspace.
Lineage
Supports findings F-01, F-02, and limitation L-03.
Custody Timeline
09:06
Original metadata export received
Platform Custodian → Evidence Custodian
Preserve approved fictional file metadata for the duplicate-folder case.
Initial verification passed.
09:11
Preserved metadata copy stored
Evidence Custodian
Protect stable reference before analysis.
Post-copy verification matched.
09:15
Working copy created
Evidence Custodian → Forensic Analyst
Authorized path, timestamp, and content-hash comparison.
Working copy matched preserved reference.
09:23
Process snapshot received
Endpoint Custodian → Evidence Custodian
Preserve fictional process and session state.
Verification passed; snapshot timing limitation noted.
09:34
Identity export received
Identity Owner → Evidence Custodian
Review approved service-identity activity during the case window.
Verification passed.
09:41
Cloud audit export received
Cloud Custodian → Evidence Custodian
Review fictional sharing, download, and administrative activity.
Verification passed; retention limitation noted.
09:48
Filtered metadata table created
Forensic Analyst
Create a fictional approved time-window subset from the working copy.
Row count, filter criteria, parent source, and output identifier recorded.
10:02
Application audit export received
Application Owner → Evidence Custodian
Reconcile delayed fictional application events.
Verification and completeness review passed.
10:18
Timeline version 2 created
Forensic Analyst
Integrate delayed application records with metadata, process, identity, and cloud events.
Parent identifiers, normalization method, changes, conflicts, and reviewer recorded.
10:45
Evidence handling review
Evidence Custodian + Incident Lead
Confirm fictional integrity, custody, lineage, access, exceptions, and readiness for reporting.
Review approved with one documented limitation and no unresolved custody gap.
Analyze the Evidence
Common Mistakes
Safe Practice Lab
Your fictional assignment
Use only the supplied fictional Northbridge records to create a complete evidence register, transfer history, access record, integrity-exception report, and derived-artifact lineage map.
Required deliverables
Scenario Decision Lab
A fictional working copy does not match the preserved reference after transfer to the analysis workspace.
Scenario Decision Lab
A fictional reviewer wants to use an analyst screenshot in the final report but the screenshot has no evidence identifier, capture context, filter state, or parent-source reference.
Defender Habits
Check Your Understanding
Choose your answers first. Explanations appear only after submission.
Portfolio Prompt
Create a fictional Digital Evidence Integrity and Chain-of-Custody Package for the Northbridge Research Archive case. Include evidence identifiers, source and owner, description, scope, receipt time, authorization reference, original and working-copy records, verification points, transfer history, access history, derived-artifact lineage, one integrity exception, corrective action, storage controls, retention, disposition, review approval, and portfolio-safety statement.
Key Takeaways
Navigation