Legal Cyber Academy
Standard or guidanceFreeCurrent

SWGDE Best Practices for Computer Forensic Acquisitions

Scientific Working Group on Digital Evidence · Version 2.1, published 2025-08-05 · 2025

Identifier: SWGDE 17-F-002-2.1

Access and status

Cost

Free

Free to read or download at source. No account, no purchase.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

SWGDE's guidance on acquiring data from computers and computer storage, including write blocking, live versus dead acquisition, verification and the handling of encrypted and self-encrypting media. The version verified here is 17-F-002-2.1 dated 5 August 2025.

Who it is for, and when

Read it when you need to justify an acquisition choice — why a logical image rather than a physical one, why a live acquisition, why verification hashes differ on re-read. It is the document to quote when an acquisition decision is challenged as non-standard.

What it does not cover

It is scoped to computers and computer storage: mobile devices are covered by separate SWGDE documents (18-F-003 and 20-F-005), and cloud sources by 23-F-004. It does not evaluate or endorse specific tools, and SWGDE disclaims any warranty as to the guidance.

Go to the source

Open at swgde.org (opens in a new tab)

https://www.swgde.org/wp-content/uploads/2025/09/2025-08-05-Best-Practices-for-Computer-Forensic-Acquisitions-17-F-002-2.1.pdf

Details

Type
Standard or guidance
Written for
Working examinerWorking examiner
Publisher
Scientific Working Group on Digital Evidence
Version verified
Version 2.1, published 2025-08-05
Year
2025
Identifier
SWGDE 17-F-002-2.1
Topics
imaging, file-systems, encryption, evidence-handling, us-federal
Checked at source
Standards are revised. Confirm the current revision with the publisher before citing this.
  • A Windows tool that mounts raw, forensic, and virtual machine disk images as complete physical disks rather than as individual volumes, which is what lets Windows and other software treat an image as a real attached drive. It also offers Windows authentication bypass, launching virtual machines from volume shadow copies, and BitLocker handling.

  • NIST's guidance on seizing, preserving, acquiring and examining mobile phones and their associated media, including the acquisition-level model (manual, logical, physical, chip-off, JTAG) that practitioners still use as shared vocabulary. It supersedes the 2007 first edition of SP 800-101.

  • The acquisition half of the job done properly with Linux command-line tools: write protection, image formats, attaching subject media, image management and transfer, integrity by cryptographic and piecewise hashing, PKI signatures and RFC 3161 timestamping, drive security (ATA passwords, Opal self-encrypting drives, BitLocker, FileVault), and difficult cases such as RAID, VM images and damaged media.

  • An NIJ special report, produced by the Technical Working Group for the Examination of Digital Evidence, covering policy and procedure, evidence assessment, acquisition, examination, documentation and reporting. It is the second guide in NIJ's digital evidence series, after the first responder guide.

  • A NIST Special Publication that sets out a four-phase forensic process (collection, examination, analysis, reporting) and applies it to four data sources: files, operating systems, network traffic, and applications. It is written for organisations building forensic capability inside an incident response function rather than for law enforcement labs.