SWGDE Best Practices for Computer Forensic Acquisitions
Scientific Working Group on Digital Evidence · Version 2.1, published 2025-08-05 · 2025
Identifier: SWGDE 17-F-002-2.1
Access and status
Cost
Free
Free to read or download at source. No account, no purchase.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
SWGDE's guidance on acquiring data from computers and computer storage, including write blocking, live versus dead acquisition, verification and the handling of encrypted and self-encrypting media. The version verified here is 17-F-002-2.1 dated 5 August 2025.
Who it is for, and when
Read it when you need to justify an acquisition choice — why a logical image rather than a physical one, why a live acquisition, why verification hashes differ on re-read. It is the document to quote when an acquisition decision is challenged as non-standard.
What it does not cover
It is scoped to computers and computer storage: mobile devices are covered by separate SWGDE documents (18-F-003 and 20-F-005), and cloud sources by 23-F-004. It does not evaluate or endorse specific tools, and SWGDE disclaims any warranty as to the guidance.
Go to the source
Open at swgde.org (opens in a new tab)https://www.swgde.org/wp-content/uploads/2025/09/2025-08-05-Best-Practices-for-Computer-Forensic-Acquisitions-17-F-002-2.1.pdf
Details
- Type
- Standard or guidance
- Written for
- Working examinerWorking examiner
- Publisher
- Scientific Working Group on Digital Evidence
- Version verified
- Version 2.1, published 2025-08-05
- Year
- 2025
- Identifier
- SWGDE 17-F-002-2.1
- Topics
- imaging, file-systems, encryption, evidence-handling, us-federal
- Checked at source
- Standards are revised. Confirm the current revision with the publisher before citing this.
Related entries
A Windows tool that mounts raw, forensic, and virtual machine disk images as complete physical disks rather than as individual volumes, which is what lets Windows and other software treat an image as a real attached drive. It also offers Windows authentication bypass, launching virtual machines from volume shadow copies, and BitLocker handling.
NIST's guidance on seizing, preserving, acquiring and examining mobile phones and their associated media, including the acquisition-level model (manual, logical, physical, chip-off, JTAG) that practitioners still use as shared vocabulary. It supersedes the 2007 first edition of SP 800-101.
The acquisition half of the job done properly with Linux command-line tools: write protection, image formats, attaching subject media, image management and transfer, integrity by cryptographic and piecewise hashing, PKI signatures and RFC 3161 timestamping, drive security (ATA passwords, Opal self-encrypting drives, BitLocker, FileVault), and difficult cases such as RAID, VM images and damaged media.
An NIJ special report, produced by the Technical Working Group for the Examination of Digital Evidence, covering policy and procedure, evidence assessment, acquisition, examination, documentation and reporting. It is the second guide in NIJ's digital evidence series, after the first responder guide.
A NIST Special Publication that sets out a four-phase forensic process (collection, examination, analysis, reporting) and applies it to four data sources: files, operating systems, network traffic, and applications. It is written for organisations building forensic capability inside an incident response function rather than for law enforcement labs.