Digital Evidence Toolkit

January 28, 2026 ยท View on GitHub

A curated collection of freely available tools and guides to assist individuals in gathering, preserving, and authenticating digital evidence.

Last Updated: January 28, 2025

Disclaimer: This repository is for informational purposes only and does not constitute legal advice. Adapt these methods to your own needs and consult legal counsel regarding evidence admissibility in your jurisdiction.

AI Disclosure: This documentation was developed with the assistance of Claude Code, an AI coding assistant by Anthropic. All content has been reviewed for accuracy, but users should verify information independently for their specific use cases.

Note on Tool Listings: The tools documented here represent a curated selection, not an exhaustive catalogue. Many categories (cloud storage, blockchain timestamping, metadata tools, etc.) have numerous additional providers and alternatives beyond those listed. We focus on well-established, accessible options to illustrate workflows rather than provide comprehensive market coverage.


How It All Connects

The diagram below shows how different components of digital evidence management work together:

flowchart TB
    subgraph CAPTURE["๐Ÿ“ท Evidence Capture"]
        direction TB
        A1[Audio Recording]
        A2[Photo/Video]
        A3[Web Pages]
        A4[Email]
        A5[Messaging]
        A6[Social Media]
    end

    subgraph VERIFY["๐Ÿ” Verification & Integrity"]
        direction TB
        V1[Checksums/Hashes]
        V2[Metadata Inspection]
        V3[Timestamps]
        V4[Blockchain Anchoring]
    end

    subgraph STORE["๐Ÿ’พ Secure Storage"]
        direction TB
        S1[WORM Media]
        S2[Cloud Storage]
        S3[IPFS/Decentralised]
        S4[Evidence Bundling]
        S5[DEM Platforms]
    end

    subgraph PROTECT["๐Ÿ”’ Security & Privacy"]
        direction TB
        P1[Device Security]
        P2[Secure Comms]
        P3[OPSEC/VPN/Tor]
        P4[Redaction Tools]
    end

    subgraph ANALYSE["๐Ÿ”ฌ Analysis & Investigation"]
        direction TB
        I1[OSINT Tools]
        I2[Digital Forensics]
        I3[AI/ML Tools]
    end

    subgraph LEGAL["โš–๏ธ Legal Framework"]
        direction TB
        L1[Chain of Custody]
        L2[Legal Considerations]
        L3[Best Practices]
    end

    CAPTURE --> VERIFY
    VERIFY --> STORE
    STORE --> ANALYSE
    PROTECT -.-> CAPTURE
    PROTECT -.-> STORE
    PROTECT -.-> ANALYSE
    LEGAL -.-> CAPTURE
    LEGAL -.-> VERIFY
    LEGAL -.-> STORE

Quick Reference Index

CategoryDescriptionKey Tools
GuidesFoundation documentsChain of custody, legal, best practices
Evidence CaptureRecording & collectionProofMode, ASR, SingleFile, eEvid
Evidence StoragePreservation & integrityS3 Object Lock, OpenTimestamps, BagIt
VerificationIntegrity & authenticityExifTool, MediaInfo, checksums
InvestigationsOSINT & forensicsMaltego, Hunchly, Timesketch
RedactionPrivacy & PII removalVideo/audio/document redaction
OPSECInvestigator protectionVPNs, Tor, secure comms
AppsPlatform-specificAndroid, iOS, desktop

Important Reading

Start here to understand the foundational concepts:


Evidence Capture

Tools and methods for capturing different types of digital evidence.

Audio

Email

  • eEvid - Certified email delivery with proof

Photo & Video

Web Pages

Messaging

Extracting and preserving chat/messaging evidence.

Social Media

Preserving posts, profiles, and social media content.


Evidence Storage

Secure storage and preservation methods.

WORM Media - Write Once, Read Many

Timestamps & Blockchain

Decentralised Storage

  • IPFS - Content-addressed peer-to-peer storage with built-in integrity verification

Checksums

Cloud Storage

  • Tresorit - End-to-end encrypted cloud storage
  • Prodatix - Immutable cloud storage with retention
  • Rclone - Sync tool for 70+ cloud providers (with GUI option)

Note: Many cloud providers offer immutable storage options (Azure Blob Immutable Storage, Google Cloud Storage retention policies, Backblaze B2, Wasabi, etc.). The tools listed above are representative examples.

Specialist Hardware

Evidence Bundling

Digital Evidence Management

  • Enterprise DEM platforms (Axon Evidence, FileOnQ) - Note: Many are law enforcement only

Metadata Inspection

Tools for examining file metadata and detecting manipulation.

  • ExifTool - Industry-standard metadata reader/writer
  • MediaInfo - Video/audio technical metadata
  • Additional Tools - Metadata Extractor, Diffusion Toolkit, Dataset Tools (including AI image metadata)

Redaction & Anonymisation

Tools for removing PII and anonymising evidence before sharing.


Investigations

OSINT and data gathering tools for research and investigations.

  • Maltego - Link analysis and OSINT platform
  • Hunchly - Web capture tool for investigations

Digital Forensics


Operational Security (OPSEC)

Protecting yourself during evidence gathering and investigations.


Information Security (InfoSec)

Securing your devices and communications.


AI Tools

AI and machine learning tools for evidence-related tasks.


Apps by Platform

Quick reference for apps organized by operating system.

PlatformApps Available
AndroidProofMode, Capture Cam, ASR, FolderSync Pro
iOSCapture Cam (limited options)
WindowsDesktop tools
macOSDesktop tools
LinuxDesktop tools

Other repositories that may assist with evidence handling:


Contributing

Contributions welcome. Please submit issues or pull requests for:

  • New tools or resources
  • Corrections or updates
  • Platform-specific guides
  • Regional legal considerations