Evidence source
A fictional system, record set, file, account, device, service, workflow, person, or business process that may contain information relevant to the approved case question.
Learn how an authorized defender identifies fictional evidence sources, evaluates their relevance and volatility, verifies source health and ownership, protects privacy and operations, chooses safe collection methods, records alternate sources, and creates a defensible collection order.
Lesson Progress
High School Intermediate • I12: Digital Forensics Basics • Lesson 2 of 8
Readiness Check
0/5 ready
Professional Hook
The fictional Northbridge archive case contains several useful sources: file metadata, identity records, a process snapshot, cloud audit records, deployment history, application events, a support report, and source-health information. One source is delayed. One folder is outside scope. Some records are volatile while others are already preserved exports. A professional collection plan must decide what to preserve first, what can wait, what should not be collected, and which alternate sources can protect the case if an expected record is unavailable.
Weak approach
Collect every fictional source in any order, work directly on originals, ignore source health, and assume more data always creates more certainty.
Professional approach
Preserve the most relevant and volatile approved evidence using safe methods, document health and lineage, minimize exposure, identify alternates, and stop at the authorization boundary.
Objective 1
Identify the major fictional evidence-source categories that may support a digital-forensics case, including file, endpoint, identity, application, network, cloud, backup, support, and business records.
Objective 2
Prioritize fictional evidence collection using relevance, volatility, accessibility, ownership, source health, privacy impact, preservation risk, duplication, and decision value.
Objective 3
Create a defensible fictional collection plan with source identifiers, owners, approved methods, collection order, expected limitations, alternate sources, and completion criteria.
Objective 4
Distinguish original evidence, preserved copies, working copies, exports, screenshots, notes, derived records, and summaries so that source lineage remains clear.
Objective 5
Recognize when collection should pause because authorization, ownership, privacy, technical safety, evidence integrity, or real-system access is unclear.
Why This Matters
Without a collection plan, a fictional team may lose volatile records, alter originals, expose unrelated information, duplicate the same source, miss an important owner, disrupt service, or spend time preserving evidence that cannot answer the case question. The plan makes priorities, methods, dependencies, gaps, alternates, owners, and completion standards visible before the deeper analysis starts.
Core Concept
Evidence value
How strongly can the fictional source answer the approved question or test an alternative?
Loss risk
How quickly could the fictional source change, rotate, expire, be overwritten, or lose context?
Collection risk
Could preservation alter evidence, expose private information, disrupt service, or cross authority?
Source health
Is delivery current, complete, accessible, correctly parsed, time-aligned, and expected to contain the event?
Alternate evidence
Which different fictional source can support the same question if the preferred source fails?
Completion proof
What shows the fictional source is preserved, verified, indexed, transferred, documented, and ready for analysis?
Key Vocabulary
A fictional system, record set, file, account, device, service, workflow, person, or business process that may contain information relevant to the approved case question.
A fictional documented order and method for preserving approved evidence while protecting integrity, privacy, availability, ownership, and source context.
How quickly fictional evidence may change, disappear, rotate, expire, be overwritten, or lose useful context.
How directly a fictional source can answer the approved case question or test an important alternative explanation.
The fictional condition of an evidence source, including delivery, completeness, retention, parsing, timestamps, ownership, accessibility, and expected event coverage.
The fictional first preserved form of a supplied record or approved acquisition that should remain unchanged and traceable.
A fictional authorized copy used for analysis so the original can remain preserved.
A fictional timeline, filtered export, table, chart, screenshot, hash list, note, or correlation result created from one or more earlier sources.
The fictional record showing which original source produced each export, working copy, screenshot, note, timeline event, finding, or report statement.
The fictional sequence in which evidence sources are preserved based on volatility, relevance, risk, ownership, dependencies, and operational constraints.
A fictional prerequisite such as owner approval, system availability, decryption authority, export capability, time synchronization, or evidence-custodian support.
A different fictional evidence source that may answer the same question when the preferred source is unavailable, delayed, incomplete, or unhealthy.
A fictional time, event type, identity, asset, file, workflow, or source condition not represented by the available evidence.
The fictional point at which the approved source is preserved, verified, indexed, transferred, documented, and ready for review under the case plan.
A fictional approved deviation from the collection plan with reason, risk, owner, alternate evidence, deadline, and reassessment trigger.
Evidence Categories
Examples
Fictional files, folders, paths, names, sizes, hashes, timestamps, permissions, ownership, version history, storage events, exports, and deletion indicators.
Evidence value
Can support what content existed, where it appeared, how copies relate, which account or process touched it, and whether the supplied set changed over time.
Important limits
Metadata may be changed by copying, synchronization, restoration, extraction, time-zone conversion, or the collection method itself.
Alternate sources
Storage audit records, application logs, cloud history, backup catalogs, deployment records, and business workflow records.
Examples
Fictional event logs, services, scheduled tasks, process records, recent items, installed applications, configuration, user sessions, and device health.
Evidence value
Can support which fictional device, service, account, process, or configuration participated in an event.
Important limits
Retention, clock drift, local alteration, collection timing, shared accounts, unsupported systems, and missing context may reduce certainty.
Alternate sources
Identity logs, application records, network telemetry, deployment records, endpoint-management data, and support history.
Examples
Fictional sign-ins, tokens, service identities, role assignments, permission changes, session events, authentication results, and account lifecycle records.
Evidence value
Can connect activity to a fictional identity, access path, role, session, or authorization state.
Important limits
An identity record does not automatically identify the human intent, device user, or exact action taken after authentication.
Alternate sources
Endpoint sessions, application logs, storage transactions, network records, ticket history, and business workflow approvals.
Examples
Fictional application events, request identifiers, job records, transaction logs, errors, API activity, service health, configuration, and deployment version.
Evidence value
Can explain how an approved workflow processed data and which service action produced an observed result.
Important limits
Application logs may be delayed, filtered, sampled, incomplete, misparsed, or missing when the service fails.
Alternate sources
Storage transactions, identity records, deployment records, process snapshots, support reports, and business records.
Examples
Fictional DNS, proxy, firewall, flow, connection, destination, source, protocol, timing, and service-routing records.
Evidence value
Can support communication between fictional systems, services, identities, or external destinations.
Important limits
A connection does not prove content, purpose, success, user intent, or every action within the session.
Alternate sources
Application requests, endpoint process connections, cloud audit events, identity sessions, and vendor records.
Examples
Fictional audit events, storage actions, sharing settings, service identities, administrative changes, API calls, object history, and platform health.
Evidence value
Can support actions performed through a fictional hosted platform and show administrative or data-access changes.
Important limits
Retention, export delay, account ownership, provider interpretation, regional time, and unavailable event types may create gaps.
Alternate sources
Application records, identity events, network telemetry, support tickets, backup records, and vendor response.
Examples
Fictional backup catalogs, restore points, image manifests, retention schedules, version snapshots, recovery tests, and storage locations.
Evidence value
Can show earlier states, missing versions, recovery alignment, and whether a condition existed before or after a change.
Important limits
Backups may be incomplete, stale, encrypted, overwritten, outside current ownership, or unsafe to restore into a live environment.
Alternate sources
File version history, deployment artifacts, configuration repositories, cloud snapshots, and business archives.
Examples
Fictional user reports, tickets, approvals, workflow schedules, case notes, ownership records, service expectations, and business impact statements.
Evidence value
Provides the real-world context needed to interpret technical activity and distinguish approved work from unexpected behavior.
Important limits
Human reports may be incomplete, delayed, mistaken, influenced by later information, or unable to prove technical details.
Alternate sources
Application, file, identity, process, transaction, and source-health evidence.
Priority Matrix
How directly can this fictional source answer the approved case question or test a meaningful alternative explanation?
Higher priority example
The source records the exact workflow, file, identity, process, or transaction under review.
Lower priority example
The source is only broadly related by vendor, department, or technology.
Record in the plan
Case question supported, competing explanation tested, and expected decision value.
How quickly could the fictional evidence change, rotate, expire, be overwritten, or lose context?
Higher priority example
Running-process, active-session, temporary, short-retention, queue, or in-memory records.
Lower priority example
Preserved reports, immutable exports, approved snapshots, archived tickets, and retained business records.
Record in the plan
Expected lifetime, overwrite risk, collection deadline, and alternate source.
Is the fictional source current, complete, accessible, correctly parsed, time-aligned, owned, and expected to contain the event?
Higher priority example
Delivery is current and completeness checks pass.
Lower priority example
The source is delayed, partially retained, misconfigured, inaccessible, or missing expected events.
Record in the plan
Health status, last verified event, delay, retention, parser state, owner, and limitation.
Could the fictional collection method alter timestamps, metadata, state, access history, content, or system behavior?
Higher priority example
Opening the only original in a tool that may write metadata or executing a live query that changes service state.
Lower priority example
Reviewing a supplied read-only export or approved verified working copy.
Record in the plan
Original-preservation method, working-copy method, verification, and stop condition.
How much unrelated fictional personal, research, credential, support, or confidential information could be exposed?
Higher priority example
Full content review across unrelated folders, accounts, or time periods.
Lower priority example
Targeted metadata and event review within an approved subject and time window.
Record in the plan
Minimization, masking, access, storage, sharing, retention, and approval conditions.
Could collection affect fictional service availability, performance, evidence generation, business workflow, or recovery readiness?
Higher priority example
A live acquisition may pause a critical service or consume limited resources.
Lower priority example
An existing export can be preserved without contacting the running service.
Record in the plan
Expected effect, maintenance window, business owner, monitoring, rollback, and fallback.
Is the fictional source owned and approved by the correct system, data, privacy, incident, partner, or vendor authority?
Higher priority example
A partner-controlled backup or vendor platform requires separate approval.
Lower priority example
The supplied source is explicitly listed in current authorization.
Record in the plan
Owner, approval, delegated authority, conditions, conflicts, and escalation path.
Does the fictional source provide new information, or is it another view of the same underlying records?
Higher priority example
A separate storage transaction record independently supports an application event.
Lower priority example
A dashboard screenshot and CSV are both generated from the same log source.
Record in the plan
Original source, transformation, duplicate relationship, and independent evidentiary value.
Source States
Ready to collect
The fictional source is relevant, authorized, owned, accessible, healthy, and safe to preserve using the approved method.
Assign identifier, preserve the original form, verify integrity, record lineage and handling, and create the approved working copy.
Collect immediately
The fictional source is both highly relevant and volatile, and delay could cause loss or material reduction in evidentiary value.
Use the approved expedited method, record time and reason, protect operations, verify the result, and notify the evidence custodian.
Collect after dependency
The fictional source is relevant but requires owner approval, service window, export support, decryption authority, privacy review, or technical preparation.
Preserve the request, assign the dependency, set a deadline, identify alternate evidence, and define escalation.
Use supplied export
The fictional case already contains an approved export that can answer the question without contacting the live source.
Preserve the export, verify its source and time range, document generation method and limitations, and avoid unnecessary live collection.
Source unhealthy
The fictional source is delayed, incomplete, misparsed, inaccessible, or missing expected events.
Document the health failure, use alternate evidence, repair and test the source, adjust confidence, and reassess when records arrive.
Outside current scope
The fictional source, subject, time window, owner, or collection method is not covered by current authorization.
Do not collect or inspect it; preserve the reference, restrict exposure, request a scope decision, and proceed only after approval.
Collection unsafe
The fictional method could alter the only original, disrupt a critical workflow, destroy volatile evidence, or expose unnecessary private data.
Stop, preserve current context, propose a safer method, create a working copy or maintenance plan, and obtain approval.
Not necessary
The fictional source adds little decision value because the approved question is already answered by stronger, less intrusive evidence.
Record why collection is unnecessary and preserve the expansion trigger that would justify revisiting the source.
Defensive Workflow
Confirm the fictional decision, scope, owners, privacy boundary, time window, and what level of confidence the collection must support.
Output: Collection objective and evidence questions.
List fictional file, endpoint, identity, application, network, cloud, backup, support, business, vendor, and source-health records that may be relevant.
Output: Evidence-source inventory with owners and identifiers.
Score fictional relevance, volatility, health, integrity risk, privacy impact, operational impact, authority, duplication, and alternate-source availability.
Output: Collection-priority matrix.
Document whether the fictional source will be preserved from a supplied export, read-only snapshot, approved image, vendor export, custodian transfer, or other authorized method.
Output: Method, owner, dependency, verification, and stop condition.
Preserve highly relevant and volatile fictional evidence first while considering operational windows, source dependencies, privacy, and safer existing exports.
Output: Ordered collection schedule and deadlines.
For every important fictional source, identify an alternate, expected gap, exception owner, escalation threshold, and reassessment trigger.
Output: Alternate-source and exception register.
Assign the fictional evidence identifier, preserve the original, verify integrity, record source lineage and handling, and create the approved working copy.
Output: Evidence register, transfer record, and verified working copy.
Compare the fictional preserved set with the case questions, source-health state, expected events, gaps, dependencies, privacy rules, and owner decisions.
Output: Collection-completion review and next-analysis handoff.
Fake Dashboard
Training dashboard for supplied fictional evidence only.
Approved evidence sources
7
Seven supplied fictional sources are covered by the current authorization.
Volatile high-value sources
2
The supplied process snapshot and delayed application records require immediate preservation and health review.
Sources not to collect
1
The unrelated research-folder content remains outside current scope and unnecessary for the approved question.
Fake SOC Alert
Source: Fake Evidence Source Health Console • Time: 09:38 AM
Fake Log Panel
09:00 CASE question='duplicate archive folder' scope='approved export workflow' 09:03 INVENTORY sources='metadata,process,identity,cloud,application,deployment,support' 09:06 PRIORITY SRC-01='metadata immediate' reason='direct artifact evidence' 09:08 PRIORITY SRC-02='process immediate' reason='volatile supplied snapshot' 09:10 PRIORITY SRC-03='identity high' health='current' 09:12 PRIORITY SRC-04='cloud high' coverage='sharing and downloads' 09:15 HEALTH SRC-05='application delayed_12m' alternate='process,storage,identity' 09:18 METHOD originals='preserve' working_copies='verified' 09:21 PRIVACY content_review='not_required' metadata_first='true' 09:24 SCOPE SRC-08='unrelated folder' collection='prohibited' 09:28 DEPENDENCY deployment_runtime='confirm version alignment' 09:32 ALTERNATE cloud='network,application,support,vendor' 09:36 COMPLETE metadata='verified' process='verified' identity='verified' 09:42 EXCEPTION application='open' owner='App-Platform' deadline='10:00' 09:54 REASSESS delayed_records='received' timeline_version='v2'
Training note: this is fake data for defensive analysis practice only.
Fictional Collection Plan
Reason
Directly records the duplicate folder, paths, sizes, timestamps, and matching hashes.
Method
Preserve supplied export as original; create verified working copy.
Dependency
Confirm exporter, generation time, scope, and time zone.
Alternate
Storage audit and backup catalog.
Limitation
Export may not show every historical metadata state.
Reason
Records the fictional export worker, child copy process, parent relationship, configuration reference, and session state.
Method
Preserve supplied snapshot and documented capture context.
Dependency
Confirm capture timing and whether the process state was complete.
Alternate
Application job records and deployment logs.
Limitation
Snapshot represents one moment and may omit earlier process activity.
Reason
Connect the approved service identity and session to the export window.
Method
Preserve approved export with source-health record.
Dependency
Confirm retention and whether session identifiers are included.
Alternate
Application request and storage transaction records.
Limitation
Authentication does not prove every later action or human intent.
Reason
Test whether fictional external sharing, public links, downloads, or administrative changes occurred.
Method
Use supplied audit export; preserve original and working copy.
Dependency
Confirm event types, retention, export delay, and platform time zone.
Alternate
Network, application, support, and vendor records.
Limitation
Absence is meaningful only within verified coverage.
Reason
May explain the export request, file operation sequence, result code, and duplicate-creation path.
Method
Preserve delayed supplied records when delivered; retain earlier source-health status.
Dependency
Delivery repair and completeness validation.
Alternate
Process, storage, identity, and support records.
Limitation
Twelve-minute delay affects timeline confidence until reconciled.
Reason
Test whether an outdated fictional configuration reference was active for the export worker.
Method
Use supplied version and deployment history.
Dependency
Confirm approved version, runtime version, and configuration source.
Alternate
Process snapshot and application startup records.
Limitation
Repository state may not equal runtime state.
Reason
Explain the approved workflow, user observation, timing, urgency, and business effect.
Method
Preserve supplied report with author and creation context.
Dependency
Confirm original wording and later edits.
Alternate
Workflow schedule and application job records.
Limitation
Human reports may be incomplete or influenced by later information.
Reason
The folder is outside the approved subjects and is unnecessary for the current case question.
Method
Preserve only the reference already present in the supplied metadata export.
Dependency
Explicit new owner and privacy approval would be required.
Alternate
None needed for the current approved question.
Limitation
No conclusion may be made about the unrelated folder content.
Analyze the Evidence
Common Mistakes
Safe Practice Lab
Your fictional assignment
Use only the supplied fictional Northbridge records to create a collection plan that protects evidence value, privacy, ownership, source health, and operational safety.
Required deliverables
Scenario Decision Lab
The fictional application audit source is twelve minutes behind, but file metadata, identity, cloud, process, deployment, and support records are current.
Scenario Decision Lab
A fictional analyst proposes opening the only original evidence package in a tool that may update access metadata.
Defender Habits
Check Your Understanding
Choose your answers first. Explanations appear only after submission.
Portfolio Prompt
Create a fictional Digital Forensics Collection Plan for the Northbridge Research Archive case. Include the case questions, source inventory, identifiers, owners, relevance, volatility, source health, privacy impact, authority, integrity risk, approved method, original and working-copy rules, collection order, dependencies, alternates, limitations, exceptions, completion criteria, and analysis handoff.
Key Takeaways
Navigation