A digital forensics triage and evidence workflow

A reproducible analysis package with acquisition details, findings, a timeline and documented evidence gaps.

Before you start

Forensic triage narrows an investigation by collecting and interpreting evidence relevant to a specific question. The first deliverable should explain what was collected, what was unavailable and which conclusions the evidence can support.

Use this workflow to plan and evaluate a targeted collection. It does not replace a full forensic acquisition when that is required. The examples distinguish a collection tool from the analysis that follows, and keep the handoff to the incident owner explicit.

Have these ready

  • A case question, target identifiers and approved collection scope.
  • A tested collection profile and sufficient controlled storage.
  • An evidence custodian and a record of collection and transfer details.

1. Choose evidence for the question

Start with a bounded question such as whether a particular account accessed a host during the incident window. Identify the artifact types, systems and time range needed to answer it. Record relevant retention limits and dependencies before evidence rotates away.

Decide whether targeted collection is sufficient or whether disk, memory, cloud or other evidence requires a separate acquisition. A filesystem artifact bundle is not a full disk image. Consider the effect of live collection on the system and coordinate timing with the incident owner, especially when containment decisions are pending.

2. Record the collection configuration

Acquire documents collection from live systems or supported images using modules and profiles. Its normal output includes a container, log and JSON report. Record the exact version and chosen profile, preserve the report and compare the requested artifact set with the actual result.

For Windows collection, DFIR ORC is a configurable framework that packages selected tools and settings. Its documentation explicitly distinguishes collection from analysis. Test the configuration against a representative system before using it at scale, and do not interpret successful execution as a verdict on compromise.

3. Check completeness before analysis

Review collection errors, access failures and empty outputs while there is still an opportunity to collect again. Confirm the target identity, collection time, clock context and expected artifact locations. Record cryptographic hashes of preserved outputs and verify them after transfer.

Keep an original copy under controlled access and document who collected and transferred it. Work from analysis copies where appropriate. A hash can demonstrate that two byte sequences match; it does not establish who created the evidence, whether the collection was complete, or whether an interpretation is correct.

4. Parse a focused set and build a timeline

Dissect’s target-query exposes plugin functions for extracting particular data from supported targets. Its documentation includes listing available functions, selecting functions and producing JSON output. Start with the relevant artifacts and keep the parser version, query and output with the case.

State the meaning and time zone of each timestamp before combining sources. Separate event time from file metadata and collection time. Correlate findings across independent artifacts where possible and keep contradictory evidence. An absence is only informative when the relevant source was present, retained and successfully parsed.

5. Deliver conclusions that can be checked

Write a short answer to the original case question with evidence references for each finding. Distinguish an observed event from the inferred sequence around it. Attach a compact timeline, the acquisition and analysis manifests, known gaps and the next collection or response decision.

Acquire’s documentation explicitly describes using its resulting container with Dissect tools such as target-query. That is a documented handoff to evaluate. For any other collector and parser combination, verify the artifact formats and metadata first rather than assuming that two forensic tools are directly compatible.

Handoff checks

Before passing the work on, confirm that:

  • The collection profile answers a stated question and records its limits.
  • Errors and missing artifacts are reviewed before the source becomes unavailable.
  • Evidence identifiers and transfer checks tie analysis back to preserved data.
  • The timeline explains timestamp meanings and clock assumptions.
  • A second analyst can reproduce a representative finding from the recorded inputs.

Tools to evaluate

These profiles document different parts of the workflow. Their inclusion is not a ranking or a claim that they form an integrated stack.

Acquire

Evaluate for targeted collection from live systems and supported images. Check artifact profiles, privileges and the acquisition report.

Dissect

Evaluate for parsing and querying supported forensic targets. Confirm that the needed plugins and source artifacts are available.

DFIR ORC

Evaluate for a configured Windows artifact collection. It collects evidence and requires a separate analysis process.

All digital forensics tools

Sources and review

Primary documentation checked on . The numbered sequence and handoff checks are editorial recommendations. Product behavior and availability may change; this guide does not report hands-on testing.

Suggest a correction