Glossary term
Acquisition
Forensic acquisition is the process of creating a defensible bit-for-bit copy of digital evidence for examination, with hash verification and chain of custody documented at each step.
Acquisition is the foundation of every forensic engagement. The original evidence must remain untouched, so every analytical step happens on a working copy. The acquisition method depends on the source. Hard drives and SSDs are imaged through a hardware write-blocker to a sterile target. Mobile devices are acquired through Cellebrite or Magnet AXIOM, with logical, file system, or physical extractions chosen based on the device, OS version, and matter requirements. Cloud sources are acquired through native eDiscovery tooling (Microsoft Purview, Google Vault) plus API-based collection where needed. Live systems require memory acquisition before any other action.
Hash values (MD5 and SHA-256) are recorded at acquisition and verified at every subsequent handling. A mismatch breaks the chain.
For Canadian counsel, the acquisition methodology is what survives or fails cross-examination. Where the acquisition method is non-standard (chip-off, JTAG, ISP), the methodology must be documented in detail and defended in the expert report.
