What is evidence tampering?¶
Evidence tampering deliberately alters, conceals, substitutes, fabricates or destroys material relevant to an investigation. A changed item is not enough, because normal use, synchronisation and retention can alter records after an incident.
Establish original state and change¶
Preserve the current item and earlier versions, hashes, audit and provider history, backups and related communications. Identify what changed, when, by which account or process, and whether authority existed.
Hashes show that content differs but not who changed it or why. Version and process evidence provide that missing context.
Support deliberate purpose¶
Current state should not be assumed original, but an unexplained difference should not be labelled tampering. Test normal application transformations, policy and synchronisation behaviour.
Provider revision data may recover deleted mailbox, cloud-document or account states. Connect integrity evidence to the timeline and surrounding actions before inferring deliberate interference or personal responsibility.
Key takeaway
Describe evidence tampering only after establishing the original state, the specific alteration, the acting process and context supporting deliberate interference.