← Back to Blogs & Insights

One of the first technical decisions in a computer investigation is whether to create a full forensic image or collect only identified folders, files and artifacts. Both methods are valid when used for the right purpose. The mistake is treating them as interchangeable without considering the investigative questions.

When a full forensic image is appropriate

A full forensic image is typically preferred when the investigation may involve deleted files, anti-forensic activity, malware, persistence mechanisms, system-level artifacts, browser evidence, USB history, user activity reconstruction or unknown data locations. The broader acquisition allows an examiner to return to the preserved evidence as new questions develop.

For intrusion and insider-threat investigations, this can be especially important. A request that initially focuses on one folder may later require log analysis, shell history, registry artifacts, link files, jump lists, browser data, cloud-sync artifacts, removable-media evidence or deleted content.

When targeted collection makes sense

Targeted collection can be highly effective in civil discovery and narrowly scoped investigations where relevant data locations are known. Examples include collecting specified project folders, user-created documents, selected mail archives, application databases or defined file types within an agreed date range.

Targeting can reduce collection volume, transfer time and privacy exposure. It is particularly useful for remote collections where moving a multi-terabyte forensic image is unnecessary for the legal scope. The collection process should still preserve metadata and document the source path, filters, timestamps, collection tool and validation hashes where applicable.

The collection method should follow the question

“Image everything” is not always proportionate, while “collect only what looks relevant” can be dangerously narrow. A proper scoping discussion should identify the alleged activity, relevant time period, expected data locations, possibility of deleted content, need for system artifacts and whether later forensic reconstruction may be required.

Remote does not mean informal

Modern forensic workflows can acquire laptops, desktops and servers remotely. The same documentation principles still apply: identify the device, record acquisition details, preserve source metadata, hash collected data when appropriate, secure the transfer, and maintain a collection log. Remote collection should be designed to minimize alteration of source data while acknowledging and documenting the effects of the collection process itself.

Practical takeaway

Choose the least intrusive collection method that still answers the technical questions reliably. For a litigation folder collection, targeted acquisition may be ideal. For a suspected compromise or data-theft matter, a full forensic image may be essential. The defensibility comes from matching method to purpose and documenting why the method was selected.

Digital Shield collection support: We assist law firms, corporations, government agencies and investigative teams with remote and onsite collections, forensic preservation, cloud data, mobile devices, collaboration platforms, custom conversions and litigation-ready reporting.

Technical references

Platform capabilities and interfaces change. These official resources provide current technical context for the topics discussed above.

NIST: Evidence ManagementNIST: Digital Investigation TechniquesNIST: Digital Evidence Preservation