SWGDE Best Practices for Digital Evidence Collection
Scientific Working Group on Digital Evidence · Version 2.0, published 2025-11-20 · 2025
Identifier: SWGDE 18-F-002-2.0
Access and status
Cost
Free
Free to read or download at source. No account, no purchase.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
SWGDE's core on-scene collection document, covering preparation, data integrity and security, acquisition approaches, hashing and documentation. The version verified here is 18-F-002-2.0 dated 20 November 2025.
Who it is for, and when
The free counterpart to ISO/IEC 27037, and the one to hand to first responders because it is concrete rather than abstract. Cite it when you need to show that a collection followed published practice and the tribunal is unlikely to have access to a paywalled ISO standard.
What it does not cover
It is a collection document — it does not cover examination, analysis or interpretation, and it is silent on legal authority for the seizure. SWGDE's own cover page warns there is no warranty as to the work product and that readers must verify on swgde.org that they are using the current version.
Go to the source
Open at swgde.org (opens in a new tab)https://www.swgde.org/wp-content/uploads/2025/12/2025-11-20-Best-Practices-for-Digital-Evidence-Collection-18-F-002-2.0.pdf
Details
- Type
- Standard or guidance
- Written for
- Working examinerWorking examiner
- Publisher
- Scientific Working Group on Digital Evidence
- Version verified
- Version 2.0, published 2025-11-20
- Year
- 2025
- Identifier
- SWGDE 18-F-002-2.0
- Topics
- evidence-handling, chain-of-custody, imaging, triage, us-federal
- Checked at source
- Standards are revised. Confirm the current revision with the publisher before citing this.
Related entries
An NIJ special report, produced by the Technical Working Group for the Examination of Digital Evidence, covering policy and procedure, evidence assessment, acquisition, examination, documentation and reporting. It is the second guide in NIJ's digital evidence series, after the first responder guide.
SWGDE Best Practices for Mobile Device Evidence Collection & Preservation, Handling and Acquisition
FreeSWGDE's guidance on the front half of mobile device work: isolating and preserving a seized handset, handling power and network state, and choosing among logical, file system and physical acquisition routes. The version verified here is 18-F-003-2.0 dated 21 August 2025.
Two maintained live Linux distributions assembled for digital forensics. CAINE 14 'Lightstream' is built on Ubuntu 24.04 and is notable for a write-blocking system that locks all block devices read-only by default, with a GUI to unblock deliberately. Tsurugi Linux ships a LAB analysis edition, a lighter Acquire edition for imaging, and the BENTO portable live-response toolkit; its current LAB release is version 26.03.
FTK Imager
Partly freeA free Windows imaging and preview tool, originally from AccessData and now distributed by Exterro, which acquired the FTK line. It creates raw, E01, and AD1 images, captures live RAM, previews file systems before acquisition, and produces hash verification reports.
NIJ's first-responder guide covering electronic device types and their potential evidence, on-scene tools and equipment, securing and documenting the scene, collection, and packaging, transport and storage of digital evidence, plus a chapter of considerations organised by crime category.