Forensic copies protect original evidence
You examine a copy, not the original, because examining something changes it.
Opening a file updates its timestamps. Running a tool writes to the disk. Work on the original and you have contaminated the thing you were trying to understand, and cannot go back. Taking a verified copy first is the step that preserves the option of doing it again properly when the first attempt goes wrong.
More on Digital forensics
- Hashes can show evidence stayed unchangedThe same short string, twice
- Timestamps need interpretationOne moment, three different times
- Memory can reveal what disk cannotIt has to unwrap itself to run
- Forensic tooling can change the thing examinedYou leave prints of your own
- Deleted does not always mean goneThe card, not the book
- Cloud forensics depends on provider evidenceYou get what comes through the hatch
