SWGDE published documents library
Scientific Working Group on Digital Evidence
Access and status
Cost
Free
Free to read or download at source. No account, no purchase.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
SWGDE's own listing of its published best practices, guidelines, technical notes, positions and considerations for digital and multimedia forensics, together with archived prior versions. As at September 2026 the library holds well over a hundred numbered documents across forensics (F), video (V), audio (A), imaging (I), photography (P), quality (Q) and multi-discipline (M) series.
Who it is for, and when
Use it as the first stop when you need a free, citable US consensus document on a specific digital or multimedia forensic task. Because SWGDE revises constantly, use the library — not a saved PDF — to check whether the version you relied on is still current before you sign a report or serve an exhibit.
What it does not cover
SWGDE states that its documents carry no warranty, that they may be revised, deprecated or sunsetted at any time, and that any quotation must include the version number. They are consensus best practices, not accreditation requirements or legal standards, and coverage is uneven — some topics have detailed documents, others none.
Go to the source
Open at swgde.org (opens in a new tab)https://www.swgde.org/documents/published-complete-listing/
Details
- Type
- Standard or guidance
- Written for
- Working examinerLawyers and courtsWorking examiner, Lawyers and courts
- Publisher
- Scientific Working Group on Digital Evidence
- Topics
- standards-development, evidence-handling, us-federal, validation
- Checked at source
- Standards are revised. Confirm the current revision with the publisher before citing this.
Related entries
A law review article by a federal judge who writes extensively on digital evidence, the Reporter to the Advisory Committee on Evidence Rules, and a leading evidence practitioner, written as Rules 902(13) and 902(14) were being adopted. It works through the authentication routes for electronic evidence and explains what the new self-authentication provisions were designed to do.
A NIST repository of documented simulated digital evidence — images and data sets with known ground truth — developed with National Institute of Justice support. Holdings include scenario images (hacking case, data leakage case), Windows registry and Unicode string-search sets, Mac and mobile images, memory images, file carving and deleted-file-recovery sets, and reference/control drives.
NIST's long-running programme that builds tool specifications, test assertions, test procedures and test data for categories of forensic function — disk imaging, hardware and software write blocking, deleted file recovery, file carving, string searching, media preparation, mobile device and cloud data extraction, Windows registry and SQLite tools — and publishes the resulting test reports with DHS Science and Technology.
A CFTT offshoot that packages NIST's test methodology so labs can run it themselves and optionally share results: distributed as bootable Linux ISOs and a portable Windows web-server build, with report templates. Current suites cover disk imaging, forensic media preparation, hardware write blocking, string searching, SQLite recovery, mobile device acquisition and cloud data extraction, with companion datasets in CFReDS.
The main peer-reviewed research journal for digital forensics. It was called Digital Investigation from 2004 through 2019 and was folded into Elsevier's Forensic Science International family in 2020, when the new title and ISSN 2666-2817 took over; the DFRWS USA, EU and APAC conferences publish their accepted research papers here as special issues.