What is evidence tampering?¶
The practical answer¶
Evidence tampering is the deliberate alteration, concealment, substitution or destruction of material relevant to an investigation.
The key evidential caution¶
The dangerous assumption is that any changed file or record proves tampering.
Normal system and user activity can alter evidence after an incident.
Potential tampering may include:
Key points¶
- editing logs
- changing timestamps
- deleting messages
- altering configuration
- replacing files
- fabricating records
- changing account details
- removing devices
- modifying cloud objects
What investigators should establish¶
Investigators should establish:
Key points¶
- what the original record was
- what changed
- when it changed
- which account or process acted
- whether the change was authorised
- what copies or versions survive
- what motive or context exists
Version history, backups, provider logs, hashes, audit records and witness evidence may help.
Evidential limits¶
Do not assume that the current state is the original state.
Likewise, do not infer deliberate tampering from an unexplained difference alone.
The system may have normal synchronisation, retention or transformation behaviour.
Preserve both the altered item and any earlier version.
Where provider or application version history exists, preserve it promptly. A changed cloud document, mailbox item or account record may be recoverable through audit and revision data even where the current user-facing view no longer shows the earlier state.
Hashes can help show that a file changed, but they do not explain who changed it or why. Combine integrity evidence with account, process, version and communication records before reaching a conclusion about deliberate tampering.
That evidential boundary matters.
Operational takeaway¶
Prove the original state, the change and the actor or process responsible before describing an alteration as evidence tampering.