High School IntermediateModule I12Lesson 3 of 8

I12.3 Evidence Integrity, Hashes, and Chain of Custody

Learn how an authorized defender protects fictional originals, verifies copies, distinguishes evidence types, records every transfer and access event, preserves source lineage, investigates integrity exceptions, and explains exactly what a hash can and cannot prove.

Lesson Progress

Evidence Integrity, Hashes, and Chain of Custody

High School IntermediateI12: Digital Forensics Basics • Lesson 3 of 8

38% complete

Readiness Check

Before You Start

0/5 ready

Professional Hook

A Finding Is Only as Trustworthy as the Evidence-Handling Record behind It

The fictional Northbridge case now contains metadata, identity, process, cloud, application, deployment, support, and source-health records. Several preserved copies and working copies must move between fictional owners, custodians, analysts, and reviewers. One failed working-copy verification appears during the process. The team must determine whether the problem came from an incomplete transfer, a wrong version, a packaging change, corruption, or a real content difference without hiding the mismatch or overstating what it proves.

Weak handling

Reuse one filename and one identifier for every copy, work directly on originals, delete failed copies, and treat a hash mismatch as proof of tampering.

Professional handling

Preserve originals, assign unique identifiers, verify at control points, record every handler and purpose, quarantine exceptions, create new verified copies, and maintain complete lineage.

Objective 1

Explain how fictional evidence integrity supports trust, reproducibility, review, transfer, analysis, reporting, and closure.

Objective 2

Distinguish original evidence, preserved copies, verified working copies, exports, screenshots, notes, and derived evidence while maintaining clear source lineage.

Objective 3

Use fictional cryptographic hash concepts appropriately as integrity checks without claiming that a matching hash proves ownership, intent, completeness, or authenticity by itself.

Objective 4

Create a complete fictional chain-of-custody record containing evidence identifiers, owners, transfers, access events, purposes, timestamps, integrity checks, conditions, and exceptions.

Objective 5

Recognize and document integrity risks involving renaming, conversion, extraction, decompression, metadata changes, unsupported tools, incomplete transfers, missing handlers, and unclear custody.

Why This Matters

Integrity Is a Documented Process, Not a Single Number

A fictional hash result can help verify that two compared data objects are identical, but trustworthy handling also requires identifiers, source ownership, authorization, preservation, verification method, transfers, access history, storage, working copies, derived-artifact lineage, limitations, exceptions, review, and disposition. A complete record allows another reviewer to understand where the evidence came from and how each conclusion was produced.

Core Concept

Use the Identity–Integrity–Custody–Lineage Model

Identity

Which exact fictional evidence object, source, owner, time window, type, version, and case question are being handled?

Integrity

Which fictional method verified the object before and after collection, transfer, copying, analysis, storage, or archive?

Custody

Who controlled, transferred, stored, accessed, reviewed, or approved the fictional evidence, when, why, and under which conditions?

Lineage

Which fictional originals produced each copy, filter, screenshot, note, timeline, exhibit, finding, and report statement?

Key Vocabulary

Evidence Integrity and Custody Terms

Evidence integrity

Confidence that fictional evidence remains complete, traceable, protected from undocumented change, and consistent with its preserved source and handling record.

Hash value

A fixed-length fictional integrity result produced from digital data. Matching values can support that two compared copies are identical under the chosen method.

Integrity verification

The fictional process of comparing expected and observed integrity information before and after transfer, copying, analysis, or storage.

Original evidence

The fictional first preserved form of an approved record or acquisition that should remain protected from analysis changes.

Preserved copy

A fictional protected copy created from an approved source and retained as a stable reference.

Working copy

A fictional verified copy used for authorized analysis so the original or preserved reference remains unchanged.

Derived evidence

A fictional filtered export, screenshot, timeline, table, note, chart, extracted file, or report item created from earlier evidence.

Source lineage

The fictional relationship connecting every derived record back to the original or preserved source that produced it.

Chain of custody

The fictional chronological record of who possessed, transferred, accessed, stored, reviewed, or modified the handling state of evidence and why.

Custodian

The fictional person or role responsible for preserving, controlling, transferring, and documenting evidence according to the case plan.

Transfer event

A fictional documented change in evidence possession, storage location, control, or access responsibility.

Access event

A fictional documented instance in which evidence was opened, copied, verified, analyzed, exported, or reviewed under an approved purpose.

Integrity exception

A fictional condition such as a mismatch, missing handler, altered metadata, incomplete copy, failed verification, or unclear transfer that requires investigation and escalation.

Verification point

A fictional planned moment when evidence integrity is checked, such as after collection, transfer, storage, working-copy creation, or final archival.

Evidence disposition

The fictional final approved action for evidence, such as retained, archived, returned, transferred, or securely deleted under policy.

Hash Concepts

What a Fictional Hash Can and Cannot Prove

What a matching fictional hash can support

When the same approved method produces the same value for two compared files, the result can support that the file contents are identical at the time of comparison.

Can support

Copy verification, transfer verification, working-copy verification, archive checks, and duplicate-content comparison.

Does not prove

Who created the file, who intended an action, whether the source is complete, whether the file is authorized, or whether every surrounding record is trustworthy.

What a fictional hash mismatch means

A mismatch shows that the compared data is not identical under the chosen method, but it does not automatically prove malicious alteration.

Can support

The need to investigate copy method, source version, transfer completeness, decompression, conversion, metadata inclusion, corruption, or actual content change.

Does not prove

Automatic proof of tampering, guilt, breach, or intentional evidence destruction.

Why method and scope matter

A fictional hash should be connected to the exact evidence object, method, tool, time, handler, and version being verified.

Can support

Reproducibility and accurate comparison between the correct files or images.

Does not prove

Comparing unrelated exports, differently packaged folders, converted files, or extracted data without documenting the transformation.

Why hash values need handling records

A fictional value alone does not explain where the evidence came from, who possessed it, how it was transferred, or which copy was analyzed.

Can support

Integrity checks when combined with identifiers, lineage, custody, storage, access, and transfer records.

Does not prove

A complete chain of custody by itself.

Why derived evidence gets its own identifier

A fictional timeline, screenshot, table, or filtered export should be identified separately while preserving its parent-source references.

Can support

Clear distinction between originals and analyst-created artifacts.

Does not prove

Replacing original evidence with a screenshot or summary.

Why verification repeats

Fictional evidence should be checked at meaningful control points rather than only once during collection.

Can support

Detection of transfer errors, storage changes, incomplete copying, wrong-file selection, and undocumented modification.

Does not prove

A guarantee that no future handling problem can occur.

Chain-of-Custody Fields

Ten Records That Protect the Evidence Story

Evidence identifier

Purpose

Provides a unique fictional reference for the exact original, preserved copy, working copy, export, screenshot, note, or derived artifact.

Fictional example

NRA-E-003-ORIG, NRA-E-003-WORK-01, or NRA-D-014-TIMELINE.

Risk if missing

Reusing one identifier for several objects makes transfers, access, and findings ambiguous.

Description and scope

Purpose

Explains what the fictional evidence is, which source or subject it covers, and the relevant time or case boundary.

Fictional example

Supplied process snapshot for the archive-export worker captured at 09:24.

Risk if missing

A vague description such as log file can cause the wrong evidence to be reviewed.

Source and owner

Purpose

Records the fictional system, export process, custodian, data owner, or provider responsible for the evidence.

Fictional example

Northbridge Archive Platform, supplied by the fictional platform custodian.

Risk if missing

Unknown ownership weakens authorization, provenance, and transfer accountability.

Collection or receipt time

Purpose

Records when the fictional evidence was created, exported, received, or preserved, including time zone and source timing limitations.

Fictional example

Received 2026-07-21 09:31 UTC-04:00; source clock reported current.

Risk if missing

Missing time-zone or source-health information can distort chronology.

Integrity information

Purpose

Records the fictional verification method, expected result, observed result, tool or process, and comparison time.

Fictional example

Preserved-copy verification matched the original supplied package.

Risk if missing

A value without object identity, method, or comparison context is difficult to reproduce.

Storage and protection

Purpose

Documents the fictional approved location, access restriction, encryption or protection state, backup, retention, and monitoring.

Fictional example

Restricted evidence repository; read access limited to incident lead, evidence custodian, and assigned analyst.

Risk if missing

Uncontrolled storage creates exposure, loss, and undocumented access risk.

Transfer history

Purpose

Records every fictional change in possession, location, custody, or control with sender, receiver, time, purpose, condition, and verification.

Fictional example

Custodian transferred working copy to assigned analyst for metadata review; verification passed.

Risk if missing

A missing handler creates an unexplained custody gap.

Access and analysis history

Purpose

Records who opened, copied, verified, filtered, exported, reviewed, or used the fictional evidence and why.

Fictional example

Analyst reviewed the verified working copy to compare paths, hashes, and timestamps.

Risk if missing

Unlogged access prevents reviewers from understanding potential changes or exposure.

Derived-artifact lineage

Purpose

Connects fictional screenshots, notes, timelines, tables, findings, and reports to the exact parent evidence records.

Fictional example

Timeline event T-07 derived from NRA-E-002, NRA-E-003, and NRA-E-005.

Risk if missing

Unsupported summaries can become detached from their original evidence.

Exception and disposition

Purpose

Records fictional mismatches, damage, incomplete transfer, out-of-scope material, restricted evidence, retention, return, archive, or deletion decisions.

Fictional example

Working copy mismatch quarantined; new copy created and verified; failed copy retained as exception evidence.

Risk if missing

Deleting or hiding exceptions can make the custody record inaccurate.

Evidence Types

Distinguish Originals, Copies, and Derived Artifacts

Original supplied evidence

The first fictional approved record received or preserved for the case.

Handling: Restrict access, preserve its original packaging and context, verify upon receipt, and avoid direct analysis changes.
Example: The original supplied metadata export package.

Preserved reference copy

A fictional protected copy retained as a stable comparison point when the original source must remain separately controlled.

Handling: Verify against the original, assign a new identifier, record parent lineage, and store with restricted access.
Example: A verified preserved copy of the process snapshot.

Working copy

A fictional verified copy used for approved sorting, filtering, indexing, annotation, or tool review.

Handling: Record creation method, verification, handler, tool, purpose, and every derived artifact.
Example: A working copy of the cloud audit export used for timeline analysis.

Filtered export

A fictional subset created from a working copy to focus on approved fields, identities, events, or time windows.

Handling: Assign a derived identifier, preserve filter criteria, parent source, row counts, exclusions, and verification.
Example: A filtered identity-event table for the approved export window.

Screenshot or visual exhibit

A fictional visual representation created for review, teaching, or reporting.

Handling: Record the parent evidence, display state, filters, time zone, capture time, creator, and limitation.
Example: A screenshot showing the fictional process parent-child relationship.

Analyst note

A fictional record of observations, questions, methods, hypotheses, decisions, and limitations.

Handling: Separate observation from interpretation, link evidence identifiers, preserve revisions, and never replace the original source.
Example: A note comparing metadata timestamps with delayed application records.

Normalized timeline

A fictional derived chronology combining events from several sources.

Handling: Preserve original and normalized times, source health, conversion method, conflicts, confidence, parent identifiers, and version history.
Example: Northbridge timeline version 2 after delayed application records arrive.

Final report exhibit

A fictional approved artifact selected to support a report finding or limitation.

Handling: Link the exact parent evidence, explain relevance, preserve masking and audience limits, and avoid unsupported conclusions.
Example: An exhibit comparing matching file hashes and different path metadata.

Defensive Workflow

Preserve, Verify, Transfer, Analyze, and Review

1

Assign the evidence identity

Create the fictional case identifier, evidence identifier, description, source, owner, subject, time window, authorization reference, and evidence type.

Output: Evidence register entry.

2

Preserve the original form

Protect the fictional original or first supplied form, record packaging and source context, restrict access, and avoid analysis changes.

Output: Original-preservation record.

3

Verify integrity

Record the fictional verification method, expected and observed result, handler, time, tool or process, and any mismatch or limitation.

Output: Integrity verification record.

4

Create the approved working copy

Copy from the preserved source using the approved method, assign a new identifier, verify the copy, and document its parent lineage.

Output: Verified working-copy record.

5

Record transfers and access

Document every fictional sender, receiver, custodian, location, time, purpose, condition, verification, and authorized access event.

Output: Chain-of-custody and access history.

6

Create and link derived evidence

Assign identifiers to fictional screenshots, filters, timelines, tables, notes, and exhibits while preserving parent records and transformation details.

Output: Derived-evidence lineage map.

7

Investigate exceptions

Quarantine fictional mismatches, incomplete transfers, damaged files, unknown handlers, wrong identifiers, altered metadata, or unsupported formats without hiding the problem.

Output: Integrity exception and corrective action record.

8

Review and archive

Confirm fictional completeness, verification, custody, access, lineage, exceptions, owner approval, retention, disposition, and portfolio-safety requirements.

Output: Evidence-handling completion review.

Fake Dashboard

Fake Northbridge Evidence Integrity Dashboard

Training dashboard for fictional evidence handling only.

Original evidence records

6

Six fictional original or first-preserved records are registered and protected.

Verified working copies

5

Five working copies passed comparison before analysis.

Open integrity exceptions

1

One failed copy is quarantined while a new verified copy and corrective record are completed.

Fake SOC Alert

Working-Copy Integrity Verification Failed

Source: Fake Evidence Integrity Console • Time: 09:52 AM

High Severity
A fictional cloud-audit working copy does not match the preserved reference after transfer to the analysis workspace.
Defensive recommendation: Stop using the failed copy, preserve and quarantine it, verify the preserved reference, review transfer and packaging records, confirm the exact source version and method, create a new approved working copy, verify the new copy, document the exception and corrective action, and continue only after the evidence custodian approves.

Fake Log Panel

Fake Northbridge Chain-of-Custody Records

training-log-viewer.log
09:06 RECEIVE evidence='NRA-E-002-ORIG' sender='Platform-Custodian'
09:07 VERIFY evidence='NRA-E-002-ORIG' result='pass'
09:11 PRESERVE evidence='NRA-E-002-PRES-01' parent='NRA-E-002-ORIG'
09:15 COPY evidence='NRA-E-002-WORK-01' parent='NRA-E-002-PRES-01'
09:16 VERIFY evidence='NRA-E-002-WORK-01' result='pass'
09:23 RECEIVE evidence='NRA-E-003-ORIG' source='Process-Snapshot'
09:34 RECEIVE evidence='NRA-E-004-ORIG' source='Identity-Export'
09:41 RECEIVE evidence='NRA-E-005-ORIG' source='Cloud-Audit'
09:47 COPY evidence='NRA-E-005-WORK-01' parent='NRA-E-005-ORIG'
09:52 VERIFY evidence='NRA-E-005-WORK-01' result='fail'
09:53 QUARANTINE evidence='NRA-E-005-WORK-01' exception='INT-01'
09:58 REVIEW transfer='incomplete_package' source_version='confirmed'
10:01 COPY evidence='NRA-E-005-WORK-02' parent='NRA-E-005-ORIG'
10:02 VERIFY evidence='NRA-E-005-WORK-02' result='pass'
10:18 DERIVE evidence='NRA-D-014' type='timeline_v2'
10:45 REVIEW custody='complete' exceptions='documented'

Training note: this is fake data for defensive analysis practice only.

Fictional Evidence Register

Northbridge Evidence Identity and Lineage Records

NRA-E-001-ORIG

Original support report

Preserved

Source

Fictional archive owner

Integrity

Verified upon receipt; no later change recorded.

Custody

Received by evidence custodian and stored in the restricted case repository.

Lineage

Parent of intake summary NRA-D-001.

NRA-E-002-ORIG

Original metadata export

Preserved

Source

Fictional archive platform

Integrity

Initial and post-transfer verification matched.

Custody

Transferred from platform custodian to evidence custodian.

Lineage

Parent of working copy NRA-E-002-WORK-01 and exhibit NRA-D-011.

NRA-E-002-WORK-01

Verified metadata working copy

Active analysis

Source

Derived from NRA-E-002-ORIG

Integrity

Verified against preserved source before analysis.

Custody

Assigned to fictional forensic analyst for path, timestamp, and hash comparison.

Lineage

Parent of filtered table NRA-D-006.

NRA-E-003-ORIG

Original process snapshot

Preserved

Source

Fictional endpoint custodian

Integrity

Verified at receipt; capture-method limitation documented.

Custody

Transferred through the evidence custodian to restricted storage.

Lineage

Parent of process map NRA-D-008.

NRA-E-004-ORIG

Original identity export

Preserved

Source

Fictional identity platform

Integrity

Verification passed after export transfer.

Custody

Received from identity owner with approved time-window statement.

Lineage

Parent of identity-event subset NRA-D-009.

NRA-E-005-ORIG

Original cloud audit export

Preserved

Source

Fictional cloud platform

Integrity

Verification passed; retention and event-coverage limitations recorded.

Custody

Vendor export transferred to platform custodian, then evidence custodian.

Lineage

Parent of sharing-check table NRA-D-010.

NRA-E-006-ORIG

Delayed application audit export

Preserved

Source

Fictional archive application

Integrity

Verification passed after delayed delivery; completeness review completed.

Custody

Application owner transferred export after source repair.

Lineage

Parent of timeline version 2 NRA-D-014.

NRA-D-014

Normalized timeline version 2

Reviewed

Source

Derived from NRA-E-002, NRA-E-003, NRA-E-004, NRA-E-005, and NRA-E-006

Integrity

Derived artifact identifier and parent-source references verified.

Custody

Created and reviewed within the fictional forensic workspace.

Lineage

Supports findings F-01, F-02, and limitation L-03.

Custody Timeline

Northbridge Evidence Transfers and Access Events

09:06

Original metadata export received

Platform Custodian → Evidence Custodian

Preserve approved fictional file metadata for the duplicate-folder case.

Initial verification passed.

09:11

Preserved metadata copy stored

Evidence Custodian

Protect stable reference before analysis.

Post-copy verification matched.

09:15

Working copy created

Evidence Custodian → Forensic Analyst

Authorized path, timestamp, and content-hash comparison.

Working copy matched preserved reference.

09:23

Process snapshot received

Endpoint Custodian → Evidence Custodian

Preserve fictional process and session state.

Verification passed; snapshot timing limitation noted.

09:34

Identity export received

Identity Owner → Evidence Custodian

Review approved service-identity activity during the case window.

Verification passed.

09:41

Cloud audit export received

Cloud Custodian → Evidence Custodian

Review fictional sharing, download, and administrative activity.

Verification passed; retention limitation noted.

09:48

Filtered metadata table created

Forensic Analyst

Create a fictional approved time-window subset from the working copy.

Row count, filter criteria, parent source, and output identifier recorded.

10:02

Application audit export received

Application Owner → Evidence Custodian

Reconcile delayed fictional application events.

Verification and completeness review passed.

10:18

Timeline version 2 created

Forensic Analyst

Integrate delayed application records with metadata, process, identity, and cloud events.

Parent identifiers, normalization method, changes, conflicts, and reviewer recorded.

10:45

Evidence handling review

Evidence Custodian + Incident Lead

Confirm fictional integrity, custody, lineage, access, exceptions, and readiness for reporting.

Review approved with one documented limitation and no unresolved custody gap.

Analyze the Evidence

Which Integrity Conclusion Is Best Supported?

The fictional preserved cloud-audit reference passed verification upon receipt.
The first working copy failed verification after transfer to the analysis workspace.
The failed copy was preserved and quarantined rather than deleted.
The transfer review identified an incomplete packaging step.
A new working copy created from the preserved reference passed verification.
The chain-of-custody record includes handlers, times, purposes, verification, exception, corrective action, and approval.

Which conclusion is strongest?

Common Mistakes

Mistakes That Weaken Evidence Integrity and Custody

Treating a matching fictional hash as proof of authorship, intent, ownership, completeness, authorization, or absence of compromise.
Treating a hash mismatch as automatic proof of malicious tampering without checking packaging, conversion, extraction, copy method, corruption, version, and tool behavior.
Recording an integrity value without identifying the exact evidence object, method, time, handler, and comparison target.
Using one fictional evidence identifier for an original, preserved copy, working copy, filtered export, screenshot, and report exhibit.
Working directly on the only original or preserved reference.
Failing to verify a fictional working copy before analysis begins.
Renaming, converting, extracting, decompressing, annotating, or filtering evidence without documenting the transformation.
Replacing original evidence with screenshots, notes, timelines, or summaries.
Failing to record who possessed, transferred, accessed, analyzed, or stored the fictional evidence.
Leaving a custody gap when evidence moves between an owner, custodian, analyst, vendor, reviewer, or storage location.
Deleting a failed copy or mismatch instead of preserving and documenting the integrity exception.
Assuming the presence of a chain-of-custody form proves that every event is accurate and complete.
Failing to connect derived fictional artifacts and report statements to parent evidence identifiers.
Publishing real hashes, paths, filenames, evidence labels, custody names, tool details, storage locations, timestamps, or internal procedures in a portfolio.

Safe Practice Lab

Build the Northbridge Evidence Register and Chain of Custody

Your fictional assignment

Evidence Identity, Integrity, Custody, and Lineage Package

Use only the supplied fictional Northbridge records to create a complete evidence register, transfer history, access record, integrity-exception report, and derived-artifact lineage map.

Required deliverables

  1. Unique identifiers for originals, preserved copies, working copies, and derived artifacts.
  2. Source, owner, description, scope, creation or receipt time, and authorization reference.
  3. Integrity method, expected result, observed result, handler, time, and verification point.
  4. Storage, protection, access, retention, and need-to-know controls.
  5. Transfer history with sender, receiver, purpose, condition, and verification.
  6. Access and analysis history.
  7. Derived-artifact parent-source map.
  8. Integrity-exception, corrective-action, approval, and final review record.
Do not hash, copy, inspect, transfer, or analyze any real evidence. Complete the lab only with fictional records displayed in this lesson.

Scenario Decision Lab

A Working Copy Fails Verification

A fictional working copy does not match the preserved reference after transfer to the analysis workspace.

Scenario Decision Lab

A Reviewer Requests a Screenshot without Parent Evidence

A fictional reviewer wants to use an analyst screenshot in the final report but the screenshot has no evidence identifier, capture context, filter state, or parent-source reference.

Defender Habits

Evidence Integrity, Hashes, and Chain-of-Custody Checklist

Check Your Understanding

I12.3 Mini Quiz: Evidence Integrity, Hashes, and Chain of Custody

Choose your answers first. Explanations appear only after submission.

1. What can a matching fictional hash most directly support?

2. What should happen after a fictional hash mismatch?

3. Why should a working copy receive a new fictional evidence identifier?

4. What belongs in a fictional chain-of-custody transfer event?

5. Which item is derived evidence?

6. What should happen when a fictional working copy fails verification?

7. Why should verification occur at several points?

Portfolio Prompt

Portfolio Prompt

Create a fictional Digital Evidence Integrity and Chain-of-Custody Package for the Northbridge Research Archive case. Include evidence identifiers, source and owner, description, scope, receipt time, authorization reference, original and working-copy records, verification points, transfer history, access history, derived-artifact lineage, one integrity exception, corrective action, storage controls, retention, disposition, review approval, and portfolio-safety statement.

Use only fictional evidence names, identifiers, handlers, storage locations, hashes, dates, times, systems, owners, and organizations.
Never present a hash as proof of intent, authorship, completeness, authorization, or absence of compromise.
Keep failed copies and mismatches visible through exception records rather than deleting them.
Link every screenshot, filter, timeline, note, exhibit, and finding to its exact fictional parent evidence.

Key Takeaways

What You Should Remember

1.Evidence integrity is a documented chain of identity, preservation, verification, custody, access, lineage, exception handling, review, and disposition.
2.A matching fictional hash can support content identity between compared objects but cannot independently prove ownership, intent, completeness, authenticity, or authorization.
3.Originals, preserved references, working copies, filtered exports, screenshots, notes, timelines, and report exhibits should have distinct identifiers and handling records.
4.Every transfer and access event should record who, when, why, which evidence object, which condition, and which verification result.
5.Derived evidence is useful only when its parent sources, transformations, filters, limitations, and review history remain visible.
6.Integrity mismatches should be preserved, quarantined, investigated, corrected, reviewed, and documented rather than hidden.
7.Portfolio artifacts should recreate the integrity workflow with clearly fictional evidence rather than exposing real evidence-handling details.

Navigation

Continue Module I12