I’m seeing PI outcomes hinge on basic digital evidence handling — last week a 48‑hour timeline built with KAPE and Timesketch got muddied when a sync client rewrote file MAC times on export. How are you preserving metadata and chain of custody during client‑consented collections (AXIOM, UFED, or provider exports), especially across jurisdictions where rules differ — no guarantees here, just comparing notes and reminding folks to do their own research.
I stopped getting MAC times mangled by imaging first and only exporting from a mounted image — hardware write‑blocker → FTK Imager E01 → mount read‑only and run KAPE/Timesketch against the mount, not the live box. For chain, I record a SHA‑256 at creation and after every hop; if you’re stuck with AXIOM/UFED/provider exports, wrap them in a store‑only ZIP immediately and hash the container too, @OP.
But i once faced a similar issue with metadata getting messed up during an export. I found that double-checking the timestamps on the original device before exporting can save a lot of headaches later on. It’s like making sure the cake is baked before icing it — no one wants a mushy middle when you cut.
This drives me nuts too! I’ve had success preserving metadata by using a write-blocker and creating an image first, but I sometimes double-check the original timestamps after exporting just to be safe, like you mentioned. Jurisdictional differences can complicate things, so I always make sure to document the entire process thoroughly. @taylor_h92, do you think adjusting our workflows a bit can help streamline the chain of custody?