DEVI Digital Forensics is a field notebook, published so the next examiner can find an answer in five minutes instead of five hours.
Each entry starts the same way: something on a device did not match what a tool displayed, or did not match what the filesystem implied, and somebody went and found out what the device was actually doing. What gets written down is the artifact, where it lives, how it was reached, and what it can and cannot support.
Independence
How to read a finding here
Everything published here is educational. It is written to help examiners know where to look, not to tell them what to conclude.
- Validate independently. Reproduce a finding against your own data before you rely on it in your work. Nothing here has been validated against your device, your extraction, or your tool version.
- Behavior changes. Forensic behavior can change between operating system versions, application versions, extraction methods, and tool versions. A field that carries useful context on one build may be absent, renamed, or populated differently on another.
- Nothing stands alone. An artifact should not be interpreted in isolation. Corroborate a finding with the other evidence available on the device and in the case.
- Parsed output is a starting point. A tool's presentation of an artifact is an interpretation. Where it matters, go to the native record the tool is reading and confirm what is actually stored there.
The language we use
We try to keep three different claims clearly separated, because collapsing them is how a useful artifact turns into an overstated conclusion.
- Observed — what we actually encountered, on a stated device, operating system, and tool.
- Indicates, or provides context — what an artifact can reasonably support alongside other evidence.
- Proves — reserved for what is technically justified. It is used rarely, and never for an artifact that merely correlates with a user action.
An import-related database field, for one concrete example, can indicate which application was associated with saving a file. It does not establish that a particular person intentionally acquired it. Those are different statements and we keep them apart.
What is not published here
Articles use technical examples only. Filenames, paths, identifiers, and values appear because they illustrate an artifact, and for no other reason.
Nothing published here contains case-identifying material: no suspect or victim names, no case numbers, no agency information, no addresses, phone numbers, account identifiers, or evidence identifiers, no investigative narrative, and no imagery from any examination.
Corrections
If a finding here is wrong, incomplete, or has stopped being true on a newer build, we would rather know. Write to contact@deviops.app. Corrections are made in place and the article records the date it was updated.