The Blank Letterhead That Led to a Domestic Terrorist—and Why Documentation is Important
There's a line I put on a slide in class that I want to put here first, because everything in this article depends on it: one hundred percent of anything anyone else will ever know about your examination comes from reading your report. Not from watching you work. Not from your institutional reputation. Not from the fact that you've been doing this for fifteen years. One hundred percent, from the document you write.
That's not a statement about writing skill (though that's an important and often overlooked part of forensics in general). It's a statement about professional obligation—one that begins well before the report in the notes you take the moment evidence arrives and the documentation you maintain every day through to the final page of your analysis.
In my experience, the mechanics of case documentation in law enforcement digital forensics cover four interlocking areas: chain of custody, note taking, worksheets and checklists, and forensic reporting. Each carries its own procedural requirements and its own ethical weight, and the ethical weight tends to get underemphasized in favor of the procedural. That imbalance is worth correcting. In Intelligence or commercial environments, notes are often left-up to the individual examiner or discouraged completely by highly-paid attorneys.
Chain of custody is the mechanism by which the law verifies that the evidence you analyzed is the same evidence that was seized, and that it arrived in your hands intact. The form is simple—a dated record of every person who received or released a piece of evidence, from seizure to court. What isn't simple is the discipline required to fill it out accurately, in real time, without gaps. A few things I tell every class: opposing counsel may not know the first thing about digital evidence artifacts or forensic methodology. They will absolutely know what a chain of custody form is supposed to look like, and they will find every anomaly in yours. Fill it out correctly. Fill it out immediately. Don't put it off. One more wrinkle worth noting: when evidence ships via commercial carrier, the carrier's name and tracking number become a "released to" on the sending end and a "received from" on the receiving end. Yes, evidence gets shipped. Your chain form needs to reflect that cleanly, and multiple chain forms may exist for a single piece of evidence depending on where it originated and how many hands it passed through on its way to your bench. The ends and beginnings have to match up.
In my opinion (which is often the source of argument amongst my colleagues), notes are the foundation everything else rests on. They need to be contemporaneous—meaning you write them as you go, not at the end of the day and certainly not at the end of the case—accurate, complete, unbiased, and clear enough that another examiner could follow your steps without having to call you. That last requirement matters more than most new examiners expect. You might not be the person who goes to trial on your own findings, or a higher-priority case might pull you away from this one for months, and when you return, "future you" will need to know exactly what "past you" already did.
I structure notes into sections: administrative details, a case summary, the analysis requested, a log of every piece of media submitted, a contact log, a tools list, a daily log, a keywords section, and a running list of people with their associated identifiers. Most of this is uncontroversial. One section, though, generates more genuine discussion in class than all the others combined.
I call it "Unknown Interest."
Unknown Interest is the section for things "that make you go hmmmm"—things that don't fit the current theory of the case. Things that seem irrelevant but feel like they might matter. Things you can't explain yet. The temptation, when you're deep in an examination, is to set aside the unexplained and focus on the evidence that's already speaking clearly. The discipline that section enforces is the opposite: write down the anomalies, return to them regularly, and review the full list before you close the case. Frequently, things that make no sense at the beginning make complete sense at the end. You're assembling a puzzle without the box lid, and you don't always know what fits where until something clicks into place.
Here's where it gets personal. Years ago, I was working a case and came across what appeared to be a blank company letterhead template sitting in Microsoft Word's templates directory on the subject's machine. The body of the document was empty—no text, no correspondence, no content of any kind. What it had was a company name, a PO Box address, and a footer at the bottom listing the organization's "corporate officers" by name. On a surface read, it looked like someone had built a template for business letters they'd never gotten around to writing (as I didn't find any saved on the computer), and there was no obvious connection to the conduct I was investigating. I almost moved past it. Something about the template—the company name, the PO Box format, the specificity of those officer names—made me log it under Unknown Interest instead. I noted the details and kept going.
As the case developed, I had the opportunity to fly out to the field office working the case and ended up reviewing progress with an intelligence analyst in the war room—the dedicated case space with the large whiteboard that looked exactly like every television procedural you've ever seen: names, photographs, and marker lines connecting individuals, groups, and entities into a web of known and suspected relationships. I was standing there taking it in when I noticed a gap. I asked her why there was no line from our subject to a cluster of names on the far corner of the board.
She said they'd been trying to make that link for years. They just didn't have anything that actually tied the two together.
"Oh, you do now," I said—and I pulled up the copy of the blank letterhead, which had every name she needed listed together in one place, right there in the footer.
She jumped out of her chair and screamed.
The connection wasn't sitting in a database. It was in a footer on an empty document in a templates directory, waiting for someone to log it and come back to it. The hunch cost me thirty seconds to document. The documentation is what made it usable.
That is why Unknown Interest exists as a dedicated section and not as a mental note you plan to revisit. Mental notes dissolve under case pressure. Documented ones don't.
Worksheets and checklists draw eye-rolls from experienced practitioners who consider them beneath their skill level. I use an analogy to cut that short: commercial pilots fly 83 hours a month and still run a preflight checklist before every flight. The checklist doesn't reflect doubt about their skill. It reflects an honest understanding that even skilled people operating under normal pressure can miss things that a systematic review would catch. Digital forensics is no different. The worksheets in circulation today are almost all derived from one examiner's work at a DEA laboratory in 2003 (hi, Gerry!) which tells you something about how slowly foundational practices evolve. They don't dictate the way you work a case; they exist as a reminder not to skip the thing you do on every case but didn't consciously think about today. If you don't like the existing templates, make your own, but have something. The checklist isn't an "end-all, be all" to your analysis. It's a useful list of tasks to make sure you hit everything you needed to.
The forensic report is where everything converges. It needs to be correct—every assertion backed by cited evidence, every citation including the evidence item number, file path, file name, and MD5 hash at minimum. It needs to be clear—active voice, proofread out loud at your desk because your ear will catch what your eye misses, and accessible to someone who has never used a command line. It needs to be appropriate for its audience: the case agent, the judge, and the jury member who is going to make a consequential decision based on your ability to explain what you found in plain language. It needs to be unbiased—inculpatory and exculpatory evidence alike, because you are not the judge, and your job is to report what the evidence says, not to build the prosecution's case for them. The structure I use runs from a cover page through an executive summary (prime beef—clear, direct, no technical jargon, responsive to the actual question the case is asking), then the media submitted, the request for analysis, the detailed technical findings, the analyst's commentary, recommendations, and attachments.
On that last item: don't scrimp on attachments. Full email lists, contact lists, complete browsing histories, every file referenced in the report body—these go into the attachments in their entirety, even if they run long. The human reader probably won't work through all of them. That's not the point. The point is cross-correlation, and increasingly, the point is that investigative tools and analytical systems will index that data against other cases, other subjects, and other jurisdictions in ways you can't anticipate when you're writing the report. Put the data in. Let the downstream systems use it.
One technique worth naming explicitly: when you need to explain a technical point to a non-technical reader—what a registry setting does, what a particular software flag means—offset that explanation in an italicized block labeled clearly as an "Analyst's Note." It keeps the narrative readable at the top level while making the technical context available to anyone who needs it. It also forces you to be precise about what you actually know versus what you're inferring, which is a discipline that pays dividends on the witness stand.
The thread running through chain of custody, note taking, checklists, and reporting is a single, consistent obligation: documentation is not the administrative tax you pay on the interesting work. It is the interesting work. The examiner who treats it that way is the examiner whose cases survive scrutiny—and the examiner who catches the hunch that everyone else would have walked past.
This post is the seventh in a series based on my course, DFOR 671: Topics of Ethics and Law in Computer Forensics, that I have taught at George Mason University for the past fifteen years. Over the next several articles, I'll be looking at the ethical, legal, and practical issues that sit underneath the work: bias, candor, privacy, professional responsibility, reporting, courtroom credibility, incident response pressure, and the messy human realities that never seem to fit neatly into a checklist.
First published on LinkedIn.