High School IntermediateModule I12Lesson 2 of 8

I12.2 Evidence Sources and Collection Planning

Learn how an authorized defender identifies fictional evidence sources, evaluates their relevance and volatility, verifies source health and ownership, protects privacy and operations, chooses safe collection methods, records alternate sources, and creates a defensible collection order.

Lesson Progress

Evidence Sources and Collection Planning

High School IntermediateI12: Digital Forensics Basics • Lesson 2 of 8

25% complete

Readiness Check

Before You Start

0/5 ready

Professional Hook

Collecting More Evidence Is Not Automatically Better

The fictional Northbridge archive case contains several useful sources: file metadata, identity records, a process snapshot, cloud audit records, deployment history, application events, a support report, and source-health information. One source is delayed. One folder is outside scope. Some records are volatile while others are already preserved exports. A professional collection plan must decide what to preserve first, what can wait, what should not be collected, and which alternate sources can protect the case if an expected record is unavailable.

Weak approach

Collect every fictional source in any order, work directly on originals, ignore source health, and assume more data always creates more certainty.

Professional approach

Preserve the most relevant and volatile approved evidence using safe methods, document health and lineage, minimize exposure, identify alternates, and stop at the authorization boundary.

Objective 1

Identify the major fictional evidence-source categories that may support a digital-forensics case, including file, endpoint, identity, application, network, cloud, backup, support, and business records.

Objective 2

Prioritize fictional evidence collection using relevance, volatility, accessibility, ownership, source health, privacy impact, preservation risk, duplication, and decision value.

Objective 3

Create a defensible fictional collection plan with source identifiers, owners, approved methods, collection order, expected limitations, alternate sources, and completion criteria.

Objective 4

Distinguish original evidence, preserved copies, working copies, exports, screenshots, notes, derived records, and summaries so that source lineage remains clear.

Objective 5

Recognize when collection should pause because authorization, ownership, privacy, technical safety, evidence integrity, or real-system access is unclear.

Why This Matters

A Collection Plan Protects Evidence before Analysis Begins

Without a collection plan, a fictional team may lose volatile records, alter originals, expose unrelated information, duplicate the same source, miss an important owner, disrupt service, or spend time preserving evidence that cannot answer the case question. The plan makes priorities, methods, dependencies, gaps, alternates, owners, and completion standards visible before the deeper analysis starts.

Core Concept

Use the Evidence Value–Loss Risk–Collection Risk Model

Evidence value

How strongly can the fictional source answer the approved question or test an alternative?

Loss risk

How quickly could the fictional source change, rotate, expire, be overwritten, or lose context?

Collection risk

Could preservation alter evidence, expose private information, disrupt service, or cross authority?

Source health

Is delivery current, complete, accessible, correctly parsed, time-aligned, and expected to contain the event?

Alternate evidence

Which different fictional source can support the same question if the preferred source fails?

Completion proof

What shows the fictional source is preserved, verified, indexed, transferred, documented, and ready for analysis?

Key Vocabulary

Evidence Collection Planning Terms

Evidence source

A fictional system, record set, file, account, device, service, workflow, person, or business process that may contain information relevant to the approved case question.

Collection plan

A fictional documented order and method for preserving approved evidence while protecting integrity, privacy, availability, ownership, and source context.

Volatility

How quickly fictional evidence may change, disappear, rotate, expire, be overwritten, or lose useful context.

Relevance

How directly a fictional source can answer the approved case question or test an important alternative explanation.

Source health

The fictional condition of an evidence source, including delivery, completeness, retention, parsing, timestamps, ownership, accessibility, and expected event coverage.

Original evidence

The fictional first preserved form of a supplied record or approved acquisition that should remain unchanged and traceable.

Working copy

A fictional authorized copy used for analysis so the original can remain preserved.

Derived evidence

A fictional timeline, filtered export, table, chart, screenshot, hash list, note, or correlation result created from one or more earlier sources.

Source lineage

The fictional record showing which original source produced each export, working copy, screenshot, note, timeline event, finding, or report statement.

Collection order

The fictional sequence in which evidence sources are preserved based on volatility, relevance, risk, ownership, dependencies, and operational constraints.

Collection dependency

A fictional prerequisite such as owner approval, system availability, decryption authority, export capability, time synchronization, or evidence-custodian support.

Alternate source

A different fictional evidence source that may answer the same question when the preferred source is unavailable, delayed, incomplete, or unhealthy.

Coverage gap

A fictional time, event type, identity, asset, file, workflow, or source condition not represented by the available evidence.

Collection completion

The fictional point at which the approved source is preserved, verified, indexed, transferred, documented, and ready for review under the case plan.

Collection exception

A fictional approved deviation from the collection plan with reason, risk, owner, alternate evidence, deadline, and reassessment trigger.

Evidence Categories

Eight Sources That May Support a Fictional Case

File and storage evidence

Examples

Fictional files, folders, paths, names, sizes, hashes, timestamps, permissions, ownership, version history, storage events, exports, and deletion indicators.

Evidence value

Can support what content existed, where it appeared, how copies relate, which account or process touched it, and whether the supplied set changed over time.

Important limits

Metadata may be changed by copying, synchronization, restoration, extraction, time-zone conversion, or the collection method itself.

Alternate sources

Storage audit records, application logs, cloud history, backup catalogs, deployment records, and business workflow records.

Endpoint and operating-system evidence

Examples

Fictional event logs, services, scheduled tasks, process records, recent items, installed applications, configuration, user sessions, and device health.

Evidence value

Can support which fictional device, service, account, process, or configuration participated in an event.

Important limits

Retention, clock drift, local alteration, collection timing, shared accounts, unsupported systems, and missing context may reduce certainty.

Alternate sources

Identity logs, application records, network telemetry, deployment records, endpoint-management data, and support history.

Identity and access evidence

Examples

Fictional sign-ins, tokens, service identities, role assignments, permission changes, session events, authentication results, and account lifecycle records.

Evidence value

Can connect activity to a fictional identity, access path, role, session, or authorization state.

Important limits

An identity record does not automatically identify the human intent, device user, or exact action taken after authentication.

Alternate sources

Endpoint sessions, application logs, storage transactions, network records, ticket history, and business workflow approvals.

Application and service evidence

Examples

Fictional application events, request identifiers, job records, transaction logs, errors, API activity, service health, configuration, and deployment version.

Evidence value

Can explain how an approved workflow processed data and which service action produced an observed result.

Important limits

Application logs may be delayed, filtered, sampled, incomplete, misparsed, or missing when the service fails.

Alternate sources

Storage transactions, identity records, deployment records, process snapshots, support reports, and business records.

Network and connection evidence

Examples

Fictional DNS, proxy, firewall, flow, connection, destination, source, protocol, timing, and service-routing records.

Evidence value

Can support communication between fictional systems, services, identities, or external destinations.

Important limits

A connection does not prove content, purpose, success, user intent, or every action within the session.

Alternate sources

Application requests, endpoint process connections, cloud audit events, identity sessions, and vendor records.

Cloud and platform evidence

Examples

Fictional audit events, storage actions, sharing settings, service identities, administrative changes, API calls, object history, and platform health.

Evidence value

Can support actions performed through a fictional hosted platform and show administrative or data-access changes.

Important limits

Retention, export delay, account ownership, provider interpretation, regional time, and unavailable event types may create gaps.

Alternate sources

Application records, identity events, network telemetry, support tickets, backup records, and vendor response.

Backup and recovery evidence

Examples

Fictional backup catalogs, restore points, image manifests, retention schedules, version snapshots, recovery tests, and storage locations.

Evidence value

Can show earlier states, missing versions, recovery alignment, and whether a condition existed before or after a change.

Important limits

Backups may be incomplete, stale, encrypted, overwritten, outside current ownership, or unsafe to restore into a live environment.

Alternate sources

File version history, deployment artifacts, configuration repositories, cloud snapshots, and business archives.

Support and business evidence

Examples

Fictional user reports, tickets, approvals, workflow schedules, case notes, ownership records, service expectations, and business impact statements.

Evidence value

Provides the real-world context needed to interpret technical activity and distinguish approved work from unexpected behavior.

Important limits

Human reports may be incomplete, delayed, mistaken, influenced by later information, or unable to prove technical details.

Alternate sources

Application, file, identity, process, transaction, and source-health evidence.

Priority Matrix

Eight Factors That Shape Collection Order

Relevance

How directly can this fictional source answer the approved case question or test a meaningful alternative explanation?

Higher priority example

The source records the exact workflow, file, identity, process, or transaction under review.

Lower priority example

The source is only broadly related by vendor, department, or technology.

Record in the plan

Case question supported, competing explanation tested, and expected decision value.

Volatility

How quickly could the fictional evidence change, rotate, expire, be overwritten, or lose context?

Higher priority example

Running-process, active-session, temporary, short-retention, queue, or in-memory records.

Lower priority example

Preserved reports, immutable exports, approved snapshots, archived tickets, and retained business records.

Record in the plan

Expected lifetime, overwrite risk, collection deadline, and alternate source.

Source health

Is the fictional source current, complete, accessible, correctly parsed, time-aligned, owned, and expected to contain the event?

Higher priority example

Delivery is current and completeness checks pass.

Lower priority example

The source is delayed, partially retained, misconfigured, inaccessible, or missing expected events.

Record in the plan

Health status, last verified event, delay, retention, parser state, owner, and limitation.

Integrity risk

Could the fictional collection method alter timestamps, metadata, state, access history, content, or system behavior?

Higher priority example

Opening the only original in a tool that may write metadata or executing a live query that changes service state.

Lower priority example

Reviewing a supplied read-only export or approved verified working copy.

Record in the plan

Original-preservation method, working-copy method, verification, and stop condition.

Privacy impact

How much unrelated fictional personal, research, credential, support, or confidential information could be exposed?

Higher priority example

Full content review across unrelated folders, accounts, or time periods.

Lower priority example

Targeted metadata and event review within an approved subject and time window.

Record in the plan

Minimization, masking, access, storage, sharing, retention, and approval conditions.

Operational impact

Could collection affect fictional service availability, performance, evidence generation, business workflow, or recovery readiness?

Higher priority example

A live acquisition may pause a critical service or consume limited resources.

Lower priority example

An existing export can be preserved without contacting the running service.

Record in the plan

Expected effect, maintenance window, business owner, monitoring, rollback, and fallback.

Ownership and authority

Is the fictional source owned and approved by the correct system, data, privacy, incident, partner, or vendor authority?

Higher priority example

A partner-controlled backup or vendor platform requires separate approval.

Lower priority example

The supplied source is explicitly listed in current authorization.

Record in the plan

Owner, approval, delegated authority, conditions, conflicts, and escalation path.

Duplication and independence

Does the fictional source provide new information, or is it another view of the same underlying records?

Higher priority example

A separate storage transaction record independently supports an application event.

Lower priority example

A dashboard screenshot and CSV are both generated from the same log source.

Record in the plan

Original source, transformation, duplicate relationship, and independent evidentiary value.

Source States

Decide Whether to Collect, Delay, Substitute, or Stop

Ready to collect

The fictional source is relevant, authorized, owned, accessible, healthy, and safe to preserve using the approved method.

Assign identifier, preserve the original form, verify integrity, record lineage and handling, and create the approved working copy.

Collect immediately

The fictional source is both highly relevant and volatile, and delay could cause loss or material reduction in evidentiary value.

Use the approved expedited method, record time and reason, protect operations, verify the result, and notify the evidence custodian.

Collect after dependency

The fictional source is relevant but requires owner approval, service window, export support, decryption authority, privacy review, or technical preparation.

Preserve the request, assign the dependency, set a deadline, identify alternate evidence, and define escalation.

Use supplied export

The fictional case already contains an approved export that can answer the question without contacting the live source.

Preserve the export, verify its source and time range, document generation method and limitations, and avoid unnecessary live collection.

Source unhealthy

The fictional source is delayed, incomplete, misparsed, inaccessible, or missing expected events.

Document the health failure, use alternate evidence, repair and test the source, adjust confidence, and reassess when records arrive.

Outside current scope

The fictional source, subject, time window, owner, or collection method is not covered by current authorization.

Do not collect or inspect it; preserve the reference, restrict exposure, request a scope decision, and proceed only after approval.

Collection unsafe

The fictional method could alter the only original, disrupt a critical workflow, destroy volatile evidence, or expose unnecessary private data.

Stop, preserve current context, propose a safer method, create a working copy or maintenance plan, and obtain approval.

Not necessary

The fictional source adds little decision value because the approved question is already answered by stronger, less intrusive evidence.

Record why collection is unnecessary and preserve the expansion trigger that would justify revisiting the source.

Defensive Workflow

Build and Execute a Fictional Collection Plan

1

Restate the approved question

Confirm the fictional decision, scope, owners, privacy boundary, time window, and what level of confidence the collection must support.

Output: Collection objective and evidence questions.

2

Build the source inventory

List fictional file, endpoint, identity, application, network, cloud, backup, support, business, vendor, and source-health records that may be relevant.

Output: Evidence-source inventory with owners and identifiers.

3

Assess source value and risk

Score fictional relevance, volatility, health, integrity risk, privacy impact, operational impact, authority, duplication, and alternate-source availability.

Output: Collection-priority matrix.

4

Define the approved method

Document whether the fictional source will be preserved from a supplied export, read-only snapshot, approved image, vendor export, custodian transfer, or other authorized method.

Output: Method, owner, dependency, verification, and stop condition.

5

Set the collection order

Preserve highly relevant and volatile fictional evidence first while considering operational windows, source dependencies, privacy, and safer existing exports.

Output: Ordered collection schedule and deadlines.

6

Prepare alternates and exceptions

For every important fictional source, identify an alternate, expected gap, exception owner, escalation threshold, and reassessment trigger.

Output: Alternate-source and exception register.

7

Preserve, verify, and index

Assign the fictional evidence identifier, preserve the original, verify integrity, record source lineage and handling, and create the approved working copy.

Output: Evidence register, transfer record, and verified working copy.

8

Review collection completeness

Compare the fictional preserved set with the case questions, source-health state, expected events, gaps, dependencies, privacy rules, and owner decisions.

Output: Collection-completion review and next-analysis handoff.

Fake Dashboard

Fake Northbridge Collection Planning Dashboard

Training dashboard for supplied fictional evidence only.

Approved evidence sources

7

Seven supplied fictional sources are covered by the current authorization.

Volatile high-value sources

2

The supplied process snapshot and delayed application records require immediate preservation and health review.

Sources not to collect

1

The unrelated research-folder content remains outside current scope and unnecessary for the approved question.

Fake SOC Alert

Critical Application Source Is Delayed

Source: Fake Evidence Source Health Console • Time: 09:38 AM

High Severity
The fictional application audit source is twelve minutes behind current time while identity, file, cloud, support, deployment, and process records are available.
Defensive recommendation: Preserve the available independent sources, document the application-source health gap, assign the source owner, validate delivery repair, retain the earlier timeline version, adjust confidence, identify expected missing events, and reassess the collection when delayed records arrive.

Fake Log Panel

Fake Northbridge Collection Planning Records

training-log-viewer.log
09:00 CASE question='duplicate archive folder' scope='approved export workflow'
09:03 INVENTORY sources='metadata,process,identity,cloud,application,deployment,support'
09:06 PRIORITY SRC-01='metadata immediate' reason='direct artifact evidence'
09:08 PRIORITY SRC-02='process immediate' reason='volatile supplied snapshot'
09:10 PRIORITY SRC-03='identity high' health='current'
09:12 PRIORITY SRC-04='cloud high' coverage='sharing and downloads'
09:15 HEALTH SRC-05='application delayed_12m' alternate='process,storage,identity'
09:18 METHOD originals='preserve' working_copies='verified'
09:21 PRIVACY content_review='not_required' metadata_first='true'
09:24 SCOPE SRC-08='unrelated folder' collection='prohibited'
09:28 DEPENDENCY deployment_runtime='confirm version alignment'
09:32 ALTERNATE cloud='network,application,support,vendor'
09:36 COMPLETE metadata='verified' process='verified' identity='verified'
09:42 EXCEPTION application='open' owner='App-Platform' deadline='10:00'
09:54 REASSESS delayed_records='received' timeline_version='v2'

Training note: this is fake data for defensive analysis practice only.

Fictional Collection Plan

Northbridge Research Archive Evidence Priorities

SRC-01

Supplied file-metadata export

1 - Immediate

Reason

Directly records the duplicate folder, paths, sizes, timestamps, and matching hashes.

Method

Preserve supplied export as original; create verified working copy.

Dependency

Confirm exporter, generation time, scope, and time zone.

Alternate

Storage audit and backup catalog.

Limitation

Export may not show every historical metadata state.

SRC-02

Supplied process snapshot

2 - Immediate

Reason

Records the fictional export worker, child copy process, parent relationship, configuration reference, and session state.

Method

Preserve supplied snapshot and documented capture context.

Dependency

Confirm capture timing and whether the process state was complete.

Alternate

Application job records and deployment logs.

Limitation

Snapshot represents one moment and may omit earlier process activity.

SRC-03

Identity and access records

3 - High

Reason

Connect the approved service identity and session to the export window.

Method

Preserve approved export with source-health record.

Dependency

Confirm retention and whether session identifiers are included.

Alternate

Application request and storage transaction records.

Limitation

Authentication does not prove every later action or human intent.

SRC-04

Cloud audit records

4 - High

Reason

Test whether fictional external sharing, public links, downloads, or administrative changes occurred.

Method

Use supplied audit export; preserve original and working copy.

Dependency

Confirm event types, retention, export delay, and platform time zone.

Alternate

Network, application, support, and vendor records.

Limitation

Absence is meaningful only within verified coverage.

SRC-05

Application audit records

5 - High after delay

Reason

May explain the export request, file operation sequence, result code, and duplicate-creation path.

Method

Preserve delayed supplied records when delivered; retain earlier source-health status.

Dependency

Delivery repair and completeness validation.

Alternate

Process, storage, identity, and support records.

Limitation

Twelve-minute delay affects timeline confidence until reconciled.

SRC-06

Deployment and configuration records

6 - Medium

Reason

Test whether an outdated fictional configuration reference was active for the export worker.

Method

Use supplied version and deployment history.

Dependency

Confirm approved version, runtime version, and configuration source.

Alternate

Process snapshot and application startup records.

Limitation

Repository state may not equal runtime state.

SRC-07

Support and business records

7 - Medium

Reason

Explain the approved workflow, user observation, timing, urgency, and business effect.

Method

Preserve supplied report with author and creation context.

Dependency

Confirm original wording and later edits.

Alternate

Workflow schedule and application job records.

Limitation

Human reports may be incomplete or influenced by later information.

SRC-08

Unrelated research-folder content

Do not collect

Reason

The folder is outside the approved subjects and is unnecessary for the current case question.

Method

Preserve only the reference already present in the supplied metadata export.

Dependency

Explicit new owner and privacy approval would be required.

Alternate

None needed for the current approved question.

Limitation

No conclusion may be made about the unrelated folder content.

Analyze the Evidence

Which Collection Decision Is Best Supported?

The fictional metadata export directly records the duplicate paths and matching hashes.
The supplied process snapshot is time-sensitive and documents the export worker and child copy process.
The application audit source is delayed by twelve minutes.
Identity, cloud, file, deployment, support, and process records remain available.
The unrelated research folder is outside current authorization.
Metadata, process, identity, and cloud records can answer the approved case question without opening file contents.

What should the fictional collection lead do?

Common Mistakes

Mistakes That Weaken Evidence Collection Planning

Collecting fictional evidence simply because it is available rather than because it supports an approved question.
Using collection order based only on convenience instead of relevance, volatility, source health, privacy, integrity risk, ownership, and operational effect.
Treating every dashboard, CSV, screenshot, and report as independent evidence even when they come from one underlying source.
Failing to preserve the original fictional export before filtering, sorting, renaming, annotating, or converting it.
Working directly on the only copy of a fictional evidence file.
Opening full content when metadata, hashes, identity, process, transaction, or business records can answer the question with less exposure.
Assuming a source is complete because it produced some records.
Treating source silence as proof when retention, delay, parsing, ownership, or expected-event coverage is unknown.
Ignoring collection dependencies such as owner approval, privacy review, maintenance window, vendor support, or decryption authority.
Collecting from an out-of-scope fictional account, folder, system, backup, or time window without approved expansion.
Using a live collection method that could change evidence or disrupt a critical fictional workflow when a safer supplied export exists.
Failing to identify an alternate source for high-value evidence.
Closing collection without checking whether every case question, source-health gap, expected event, dependency, and limitation has been addressed.
Publishing real-looking evidence identifiers, paths, filenames, logs, contacts, system names, hashes, timestamps, or internal collection procedures in a portfolio.

Safe Practice Lab

Create the Northbridge Fictional Collection Plan

Your fictional assignment

Evidence Source Inventory and Collection Order

Use only the supplied fictional Northbridge records to create a collection plan that protects evidence value, privacy, ownership, source health, and operational safety.

Required deliverables

  1. Evidence-source inventory with identifiers and owners.
  2. Relevance, volatility, source-health, privacy, authority, and integrity-risk ratings.
  3. Approved method, original-preservation rule, working-copy rule, and verification step.
  4. Collection order with deadlines and dependencies.
  5. Alternate source and expected limitation for every high-value record.
  6. Source-health exception and reassessment trigger.
  7. Out-of-scope and not-necessary decisions.
  8. Collection-completion checklist and analysis handoff.
Do not collect any real evidence. Build the plan only from the fictional records displayed in this lesson.

Scenario Decision Lab

The Application Source Is Delayed

The fictional application audit source is twelve minutes behind, but file metadata, identity, cloud, process, deployment, and support records are current.

Scenario Decision Lab

A Live Collection Could Alter the Only Original

A fictional analyst proposes opening the only original evidence package in a tool that may update access metadata.

Defender Habits

Evidence Sources and Collection Planning Checklist

Check Your Understanding

I12.2 Mini Quiz: Evidence Sources and Collection Planning

Choose your answers first. Explanations appear only after submission.

1. Which factor should most strongly influence fictional collection priority?

2. Why should a supplied fictional export sometimes be used instead of contacting the live source?

3. What makes a fictional source volatile?

4. What should happen when a critical fictional source is delayed?

5. Which item is derived evidence?

6. What should happen when a fictional evidence source is outside the approved scope?

7. When is fictional collection complete?

Portfolio Prompt

Portfolio Prompt

Create a fictional Digital Forensics Collection Plan for the Northbridge Research Archive case. Include the case questions, source inventory, identifiers, owners, relevance, volatility, source health, privacy impact, authority, integrity risk, approved method, original and working-copy rules, collection order, dependencies, alternates, limitations, exceptions, completion criteria, and analysis handoff.

Use only fictional systems, accounts, files, logs, identities, owners, dates, methods, paths, hashes, records, and organizations.
Prioritize evidence by decision value and loss risk rather than by convenience or volume.
Treat dashboards, screenshots, exports, and summaries from one underlying source as related rather than independent.
Make out-of-scope, not-necessary, unsafe, delayed, and conditionally approved sources visible in the plan.

Key Takeaways

What You Should Remember

1.A forensic collection plan connects approved case questions to specific evidence sources, owners, methods, priorities, risks, alternates, and completion standards.
2.Evidence value, volatility, source health, integrity risk, privacy, authority, operational impact, and duplication should shape collection order.
3.Originals should remain preserved while analysis occurs on verified working copies with documented lineage.
4.Source silence is not reliable when delivery, retention, parsing, accessibility, ownership, or expected-event coverage is uncertain.
5.Alternate evidence should come from genuinely different relevant sources whenever possible.
6.Out-of-scope, unnecessary, unsafe, or ownership-unclear evidence should not be collected without a documented decision.
7.Portfolio artifacts should recreate the collection workflow with clearly fictional evidence rather than exposing real systems or private records.

Navigation

Continue Module I12