Digital evidence is not only the content of a file. It is also everything the system recorded while that file was created, opened, copied and moved. Timestamps, user attribution, device identifiers and application artefacts often establish more about what happened than the document itself.
That information is also the first thing to disappear. In most matters we see, the metadata that would have answered the question was destroyed by ordinary IT activity in the days after the incident, before anyone thought to preserve anything.
What metadata establishes
Content tells you what a document says. Metadata tells you where it came from, who touched it and when.
In practice this is what allows an examiner to build a timeline. A file with a creation date later than its last modified date has usually been copied rather than authored. A document whose author field does not match the account that saved it points to a different origin. Application artefacts left behind by editing software can show how long a file was open and how many times it was revised.
None of these are conclusive on their own. Together they establish whether an account of events is consistent with what the systems actually recorded.
How it gets destroyed
Most metadata loss is accidental and well intentioned.
Copying files to a network share or a USB drive rewrites timestamps. Attaching a document to an email strips most of what was embedded in it. Uploading to cloud storage often replaces the original with a re-encoded version. Antivirus scans, backup jobs and endpoint agents all touch files and leave their own marks on top of the ones that mattered.
Rebuilding a compromised machine removes the artefacts entirely. So does restoring from a backup taken after the event.
By the time an organisation decides an investigation is warranted, the systems have usually been running normally for a week or more. The evidence has not been hidden. It has been overwritten.
What to preserve
The general rule is to preserve the environment rather than the files.
A forensic image of the relevant device captures the file system as it stands, including deleted content and artefacts that a file copy would miss. Where imaging is not practical, preserving system and application logs, endpoint telemetry and mail server records will often be enough to establish the sequence of events.
What matters most is stopping the routine activity that overwrites evidence. That means taking the device out of service rather than continuing to use it, and suspending automated processes that write to it.
When to stop and ask
Organisations frequently attempt an initial look themselves before deciding whether to engage anyone. That is reasonable, and it is also where most evidence is lost.
Opening files to see what is in them changes their access times. Searching a mailbox can alter message state. Copying a folder to review it elsewhere resets everything about it.
If there is a realistic prospect that a matter will end up in a legal, regulatory or disciplinary process, the sequence is worth getting right. A short conversation before anyone touches the systems costs very little and preserves options that cannot be recovered later.





