Digital forensics and eDiscovery: Your questions, answered
Key takeaways
- You can only review what you collect. Review doesn’t create evidence; it reveals evidence that was collected. If critical data isn’t acquired during collection, it won’t exist for investigators or attorneys to find later.
- The goal is the relevant data, not more data. Targeted collection and thoughtful culling help teams avoid over-collection while still capturing what matters, and effective discovery scoping balances date and time ranges, data types, and context.
- The depth of your collection determines the depth of your evidence. A full file system extraction reaches the encrypted apps and system-level artifacts that prove who was behind a device, and mobile and cloud are increasingly where the evidence lives.
- Engage digital forensics early. Vanishing data has a narrow recovery window, so the most important decision is involving a digital forensics expert or forensic service provider before collection begins.
eDiscovery is getting more complex. Relevant evidence is now spread across multiple custodians, endpoints, cloud platforms, mobile devices, and collaboration tools, and many traditional workflows weren’t designed for that volume or variety.
The result is predictable: over-collection, missed evidence, and unnecessary cost and risk because investigators don’t yet know what data is available.
That’s where digital forensics changes the equation, helping teams identify and collect more precisely and build a defensible process from the start.
In a recent Ask Me Anything, Justin Fitzsimmons, a former assistant state’s attorney and Jeff Rutherford, a retired FBI Special Agent digital forensic examiner, answered some of the most common questions legal and investigative teams face in eDiscovery.
How should I handle privileged information like attorney-client communications that I come across during a collection?
The safest course of conduct is to isolate it immediately. Tag the material, separate it out, and make sure no one accesses it until the appropriate attorneys, or the company, have reviewed it and decided how to proceed.
Jeff described how the FBI handled this: examiners often created a new, derivative case file so no one downstream was exposed to the privileged material.
Justin added that the same discipline applies to other potential privileged data, including doctor-patient and, in some contexts, teacher-student records. Exercise particular caution when reviewing materials that may have been inadvertently produced by an opposing party and could contain privileged communications. Reviewing inadvertently produced privileged material can disqualify an attorney or investigator from further participation in the case, potentially undoing months of preparation and case development.
How do we strike the balance between over-collection and missing data?
These are opposite ends of the spectrum, and they require different approaches. Missing data is often identifiable and correctable with the right tools and expertise. Over-collection is more difficult because collection decisions are often made before investigators know which data will ultimately prove significant.

Justin emphasized a deliberate approach to collection, encouraging investigators to target the data needed to answer the investigative questions rather than collecting everything that might be available. Jeff noted that recent EU rulings have made date and time ranges central to defensible scoping. Both emphasized that date ranges are only one element of a sound scoping strategy, as many valuable artifacts lack timestamp information.
In a conspiracy case, for instance, a contact list has no date metadata, or the database it comes from may be outside of the authorized range, yet it demonstrates the connection between eight co-conspirators saved under their criminal nicknames. The better approach is to explain to the court why certain data is relevant, based on content and context, rather than letting a rigid date range obscure how the technology actually stores information.
The takeaway: thoughtfully narrow the data at the forensic stage before it reaches the review platform, while ensuring every decision can be clearly explained and documented.
What’s the difference between a logical, category-based, and full file system extraction and why does it matter?
Jeff used a memorable analogy. Imagine walking up to a locked file cabinet:
A logical extraction is like reading only the papers sitting on top, what the user is interacting with. A full file system gets you into the locked drawers.”
Jeff Rutherford
Forensic Consultant, Magnet Forensics
That locked drawer is where the encrypted communication apps and system-level artifacts live. In one traffic accident investigation, only a full file system extraction revealed that the user had unlocked the phone and launched an app as the crash occurred. Whereas a logical or communications-only extraction would not have revealed any data, have shown nothing, because the proof lived in the system-level data, not in texts or calls.
Justin framed the legal significance as devices containing digital artifacts consisting of both digital footprints and digital exhaust:
Digital footprints reflect a user’s intentional actions. Digital exhaust consists of the background system artifacts that help attribute those actions to a specific user. Footprints help establish the elements of an offense; exhaust strengthens user attribution. Correlating both across multiple data sources produces a more complete and reliable reconstruction of the underlying events.
How do you make sure digital evidence holds up in court?
Once the examination is complete, Justin recommends that a lawyer should be able to answer three foundational questions before relying on the evidence:
QUESTION 1
Can the chain of custody be established from collection through presentation in court?
QUESTION 2
Can the integrity and authenticity of the data be demonstrated, including that it has not been altered?
QUESTION 3
Can the examiner explain what the data is, where it came from, and how it was recovered?
Answering these questions early helps ensure the evidence can be authenticated, its integrity established, and its significance clearly explained to the court.
How difficult is it to get information from messaging apps designed to vanish like Snapchat, Signal, and WhatsApp?
As with much in digital forensics, it depends, but the right tools give you a real chance. A Magnet Verakey extraction can recover keychain data, which provides the cryptographic keys needed to decrypt supported application data.
Much of this “vanishing data” resides in operating system databases that are automatically overwritten or deleted during normal device operation, without any user interaction. Recovering it requires collecting the device before those artifacts disappear and using forensic tools capable of extracting and analyzing that data.
Jeff noted that in at least one documented case, messages already deleted from a third-party app were reconstructed from the iPhone’s notification data. The alerts lingered in system-level data even after the app’s own database was over written.
There’s also a second location of potential data: the cloud. If a user backs up their third-party communication app conversations to Google Drive, those messages may reside in the Google cloud unencrypted and relatively easy to access. Even though the collection window on the device vanishes quickly, making time to evidence critical, there’s often a parallel opportunity to recover the same data from remote storage.
When I have a forensic report, can I just admit the whole thing into evidence?
In most cases, no. Admitting an entire report implies that everything in it is relevant to the case, which is almost never true. There’s usually a great deal of data on a device that has nothing to do with the matter, and relevance is foundational to admissibility
The report is not evidence. The report is simply a report. It points to the digital artifacts, which are the evidence.”
Justin Fitzsimmons
Technical Prosecutor Lead, Magnet Forensics
Justin illustrated the point with a simple analogy. Imagine Jeff is processing a crime scene and observes a pair of red shoes next to the victim. He documents that observation in his crime scene report. The report is not the evidence — it’s a record of what Jeff observed. The evidence is the shoes.
The same principle applies to digital evidence. If Jeff documents that a forensic examination recovered an image from a device depicting those same red shoes, the report is still not the evidence. It is a record of the examiner’s findings. The evidence is the image itself. A forensic report documents what was recovered and analyzed, but it does not make every artifact within that report relevant or admissible.
Justin noted that this is a common misconception among inexperienced trial lawyers. Rather than offering the entire report, lawyers should identify, authenticate, and introduce only the specific evidence that is relevant to the issues before the court.
When is the best time to get a digital forensics expert or a forensic service provider involved in a case?
Engaging your digital forensics team or forensic resources early helps ensure the appropriate collection strategy and acquisition method are used from the outset, maximizing the data available for forensic analysis.
That includes recovering full file system artifacts, supported encrypted application data, and information stored in system databases that may not be recoverable through other acquisition methods.
Early involvement is also critical for preserving “vanishing data,” information stored in operating system databases that are routinely overwritten or deleted during normal device operation. Once that data is gone, it often cannot be recovered.
The bottom line
Modern eDiscovery requires more than fast review. It starts with identifying the right data and making deliberate collection decisions from the outset.
Magnet Forensics complements review platforms by helping legal and investigative teams identify, collect, and assess the right data before review begins, reducing unnecessary cost and improving the efficiency of downstream review.
Get the right evidence, earlier. Watch the full Ask Me Anything to see how forensic-grade collection strengthens eDiscovery from the start.
Frequently asked questions about eDiscovery
Admissibility starts at the point of collection, not during review. Collection defines the evidentiary ceiling of an investigation. Data that is not acquired at the outset cannot be reconstructed through downstream processing, analytics, or review.
Key principles:
- Collect the right data, not just more data
- Preserve metadata and chain of custody
- Ensure forensic integrity from the start
This approach reduces risk, prevents rework, and strengthens outcomes in legal or investigative contexts.
Balancing over-collection and missed evidence requires precision, not volume.
Best practices include:
- Targeted, context-driven data collection (not “collect everything”)
- Thoughtful culling before review
- Avoiding overreliance on date ranges alone
Digital forensics strengthens eDiscovery by providing earlier access to a broader range of digital evidence and deeper insight into its significance. It enables legal teams to:
- More completely identify relevant evidence
- Collect from a broader range of digital sources, including mobile devices, computers, and cloud platforms
- Uncover hidden or system-level artifacts that traditional collection methods may miss
By providing earlier access to data and deeper analysis of digital evidence, digital forensics helps reduce downstream review costs, improve the accuracy of evidence identification, and build stronger, evidence-driven case strategies.
The type of extraction determines the depth of evidence recovered from a device.
- Logical extraction: captures user-visible data (e.g., messages, files)
- Full file system extraction: captures deeper system-level artifacts, encrypted app data, and hidden evidence
Full file system extraction is often required to:
- Prove user activity on a device
- Access encrypted or deleted data
- Correlate user actions with system behavior
Logical extraction tells you what happened. Full file system extraction helps you prove how, when, and by whom it happened.
Admissibility depends on maintaining a strong chain of custody and following a structured process:
- Acquire the data
- Authenticate its integrity
- Analyze it in a forensically sound manner
Legal teams must also validate:
- The right data has been collected
- Data integrity (no changes occurred) and preserved metadata
- Complete audit trail
This discipline allows teams to demonstrate where evidence came from, who handled it, and how its content was not changed during that process.
Privileged data (e.g., attorney-client communications) should be isolated immediately.
Recommended approach:
- Tag and segregate privileged materials
- Restrict access until legal review
- Maintain strict handling protocols
Improper exposure can compromise cases, disqualify team members from participation, and expose individuals or organizations to legal sanctions, regulatory penalties, professional discipline, or other remedial action.
In some cases, yes, depending on timing and data sources.
Recovery methods may include:
- Extracting device-level artifacts (e.g., notification data)
- Recovering encryption keys from system storage
- Accessing cloud backups (e.g., Google Drive for WhatsApp)
However, many of these data sources are time-sensitive and may disappear quickly, making early collection critical.
As early as possible, ideally before collection begins.
Early involvement enables:
- Better scoping and planning
- Capture of short-lived data
- Access to deeper evidence sources
- More complete early case assessment
Delays can result in lost evidence and reduced defensibility.
Yes. Modern eDiscovery workflows are designed to scale seamlessly from foundational capabilities to more advanced and enterprise-grade approaches without requiring teams to rebuild processes or abandon existing tools.
This scalability enables teams to:
- Expand data coverage (endpoints, cloud, mobile, collaboration tools)
- Introduce forensic-grade collection when needed
- Add deeper analysis without interrupting review workflows
The result: teams can mature their capabilities over time while maintaining continuity, defensibility, and operational efficiency.