No Shipping, No Downtime, Nationwide

Remote E-Discovery CollectionExaminer Supervised Acquisition Anywhere in the United States

Custodians are rarely in the same city as the lab, and few businesses can hand over a working laptop for a week. Remote collection solves both problems. An Elite Digital Forensics examiner acquires the computer, mailbox, cloud account or mobile device over an encrypted connection, hashes the data at the source, verifies it on receipt, and documents the same chain of custody a lab acquisition would produce.

Updated August 2026 · Reviewed by Elite Digital Forensics examiners · Remote and on site service nationwide

Part of our nationwide E-Discovery services

Same dayRemote sessions are frequently scheduled within one business day of engagement.
EncryptedData is encrypted in transit and at rest, with hashing performed at the source before transfer.
No shippingDevices stay with the custodian, which avoids loss in transit and business disruption.
50 statesRemote collection nationwide, with on site examiners scheduled when a matter requires it.

Quick answer. Remote E-Discovery collection is the acquisition of electronically stored information from a device or account in another location, performed under examiner supervision over an encrypted connection. A collection agent or supervised session captures a full or targeted image, hash values are calculated at the source and verified on receipt, and the process is documented in a chain of custody record. For most computer, email and cloud sources it is forensically equivalent to an in person acquisition, is faster to schedule, and avoids shipping devices or taking custodians offline for days.

Common questions, answered in one line

QuestionShort answer
What is remote collection?Examiner supervised forensic acquisition of a device or account over an encrypted connection.
Is it forensically defensible?Yes. Hashing at the source, verification on receipt and a documented chain of custody.
Do we ship the laptop?No. The device stays with the custodian and remains usable outside the collection window.
What can be collected remotely?Windows and macOS computers, mailboxes, cloud drives, collaboration tools and many mobile sources.
What cannot?Damaged or encrypted devices needing lab work, some full physical phone images and air gapped systems.
How long does it take?Targeted collections often finish in hours; full images depend on volume and upload bandwidth.
Does the custodian need technical skill?No. They install a provided agent or join a supervised session and follow instructions.
What documentation is produced?Acquisition worksheet, hash manifest, activity log and chain of custody record.

How Remote Collection Works

Remote collection replaces the physical trip, not the forensic method. The examiner still controls scope, tooling, hashing and documentation. What changes is how the examiner reaches the data.

Agent based computer collection

The custodian receives a link to a small collection utility with a one time credential. The examiner defines the scope, whether that is a full disk image or specific paths, mail stores, user profiles, date ranges and file types. The utility reads the source without writing to it, hashes each item or the entire image, and uploads to an encrypted evidence endpoint. The examiner monitors progress, verifies hashes on receipt and removes the utility when the collection is complete.

Supervised session collection

Where an agent cannot be installed, the examiner joins a screen shared session and directs the acquisition step by step while recording the session. This approach is common on tightly managed corporate endpoints and on systems where a security team requires visibility into every action taken.

Cloud and mailbox collection

Cloud sources are collected through native administrative and legal hold interfaces rather than through the endpoint. Microsoft 365 and Google Workspace expose export mechanisms, hold capabilities and audit logs that preserve server side metadata. Because these interfaces are reached over the internet by design, cloud collection is inherently remote.

Mobile collection by mail in kit or supervised session

Many mobile matters are handled with an encrypted backup collection performed in a supervised session, or with a prepaid, tracked shipping kit when a deeper extraction is required. Where a full physical extraction is necessary, the device generally has to reach an examiner in person.

Why Remote Collection Holds Up

  • Read only acquisition, so the source device is not altered by the collection
  • Hash values calculated at the source before transfer and re verified after receipt
  • Every acquisition action written to a log that records time, scope and result
  • Session recordings where the examiner directs the custodian, so the method is reviewable
  • Encryption in transit and at rest, with access limited to assigned examiners
  • A written chain of custody that begins at acquisition rather than at receipt of a shipped drive
  • A qualified examiner available to testify to method, scope and verification

Opposing counsel occasionally argues that a remote collection is inferior by definition. The response is technical and documented: the hash recorded at the source matches the hash verified in the evidence environment, the acquisition log shows what was read, and the examiner who supervised the process can testify. That record is often stronger than a shipped drive whose contents were copied by internal staff before it left the building.

Sources We Collect Remotely

SourceTypical remote scopeNotes
Windows laptops and desktopsFull disk image or targeted profile, mail store and artifact collectionRegistry, event logs, LNK, shellbag and USB artifacts included on request
macOS computersFull or targeted collection of user data, mail and system artifactsFull disk access and, on Apple silicon, an administrator credential are required
Microsoft 365Mailbox, OneDrive, SharePoint and Teams content plus unified audit logHolds can be applied before export
Google WorkspaceGmail, Drive, Chat and Calendar via Vault, plus admin audit logsVault retention and hold coverage are confirmed first
File servers and network storageTargeted share collection with permissions and path preservationScheduled outside business hours where volume is large
Collaboration platformsSlack, Teams, Box and Dropbox exports with membership and sharing recordsExport capability depends on the licensed plan
Mobile devicesEncrypted backup or supervised logical extractionDeeper extractions may require the device in hand

When Remote Collection Is Not the Right Choice

Physically damaged devices

A drive with mechanical failure or a phone with a broken board requires lab handling and, in some cases, chip level recovery.

Full physical mobile extraction

Advanced extraction methods generally require the examiner to have possession of the handset.

Air gapped or restricted systems

Classified, industrial control and isolated environments frequently prohibit outbound connections entirely.

Very large volumes on thin connections

A multi terabyte image over a slow upload link can take longer than shipping an encrypted drive with tracking.

Court ordered on site protocols

Some orders and neutral examiner protocols specify in person acquisition and witnessed handling.

Uncooperative custodians

Remote collection depends on custodian participation. Where cooperation is doubtful, on site acquisition removes the variable.

We tell counsel plainly when a matter calls for on site acquisition rather than pushing a remote workflow that will be criticized later.

What We Need to Start

  • Confirmation of lawful authority over the device or account, and the identity of the person authorizing the collection
  • Custodian names, roles, locations and the systems each one used
  • Whether the endpoint is company managed and whether administrative rights are available
  • Disk encryption status and recovery credentials where applicable
  • Cloud tenant administrator access or a designated administrator to run exports under our direction
  • Scope parameters: date ranges, custodians, file types, mailboxes, folders and keyword criteria
  • Any ESI protocol, preservation letter, subpoena or court order that governs the collection
  • A collection window that works for the custodian, including after hours where downtime matters

Cost, Speed and Scheduling

Remote collection usually costs less than the equivalent on site engagement because there is no travel, no shipping and less business disruption. Cost is driven by the number of custodians, the number of sources per custodian, the volume acquired and whether the acquisition is full or targeted. Cloud collections are priced on volume and export complexity rather than travel.

FactorEffect on timeline
Targeted computer collectionOften complete within a few hours per custodian
Full disk image over remote connectionDriven by drive size and upload bandwidth, commonly overnight
Mailbox exportHours for a single mailbox, longer for large or multi year archives
Cloud drive collectionDepends on file count and API throughput at the provider
Multiple custodiansCollected in parallel where bandwidth and licensing allow
Preservation onlyHolds can usually be applied the same day, before collection is scheduled

Where a duty to preserve has attached and the schedule is tight, preservation comes first. Holds and forensic preservation stop the clock on automatic deletion so collection can proceed in an orderly sequence rather than in a rush.

How Elite Digital Forensics Helps

We scope the matter with counsel, apply preservation where a duty has attached, then schedule remote acquisition around the custodian's working hours. The examiner controls scope and tooling, verifies hashes on receipt, and delivers an acquisition worksheet, hash manifest, activity log and chain of custody record. From there the collection moves into processing, review support or forensic analysis, and our examiners remain available to testify about how the data was acquired.

About Elite Digital Forensics

Elite Digital Forensics is an independent digital forensics firm providing nationwide E-Discovery services, computer and mobile device forensics, cloud and email investigations and expert witness testimony. Our examiners include former law enforcement forensic examiners and court qualified expert witnesses. We work for law firms on both sides of the docket, for corporations and in house legal departments, and for insurers. When retained through counsel, our work is generally treated as attorney work product prepared in anticipation of litigation.

Frequently asked questions

Is remote E-Discovery collection as defensible as an on site collection?

For most computer, mailbox and cloud sources, yes. The forensic requirements are unchanged: read only acquisition, hash values calculated at the source and verified after transfer, an activity log of what was read, encryption in transit and at rest, and a written chain of custody. A qualified examiner supervises the acquisition and can testify to method and verification.

Do we have to ship devices to your lab?

Usually not. The device stays with the custodian. A small collection utility or a supervised session is used to acquire the data, and the custodian can keep working outside the collection window. Shipping is reserved for damaged devices, deep mobile extractions and matters where a protocol requires physical possession.

Will the custodian need technical expertise?

No. The custodian installs a provided utility with a one time credential or joins a screen shared session. The examiner defines and controls the scope, monitors the acquisition and verifies the result. Instructions are written in plain language and support is available throughout the session.

Can you collect from a Mac?

Yes. macOS collection requires full disk access for the collection utility and, on Apple silicon systems, an administrator credential. Once access is granted, targeted or full acquisition proceeds with the same hashing and documentation used on Windows systems.

Can you preserve data before collecting it?

Yes, and it is often the first step. Litigation holds in Microsoft 365 or Google Vault can typically be applied the same day, which stops retention policies and user deletion from removing potentially relevant material while collection is scoped and scheduled.

How is the data protected during transfer?

Data is hashed at the source, encrypted in transit over an authenticated connection, and stored encrypted in an evidence environment with access restricted to assigned examiners. Access is logged. Hash values are recalculated on receipt and compared with the acquisition values before any processing begins.

What happens if the connection drops mid collection?

Collections resume rather than restart. The utility tracks progress and continues from the interruption point, and the final verification step confirms the completed acquisition matches the source hash values. Interruptions are recorded in the acquisition log.

Can you collect a phone remotely?

Often yes, through an encrypted backup or supervised logical extraction that captures messages, call logs, media and much app data. A full physical extraction, which reaches deeper into deleted content, generally requires an examiner to have the handset in hand.

References and authoritative sources

  1. Federal Rule of Civil Procedure 26, duty to disclose and general provisions governing discovery. law.cornell.edu
  2. Federal Rule of Civil Procedure 34, producing documents and electronically stored information. law.cornell.edu
  3. Federal Rule of Civil Procedure 37(e), failure to preserve electronically stored information. law.cornell.edu
  4. Federal Rules of Evidence 902(13) and 902(14), self authentication of electronic records and hash verified copies. law.cornell.edu
  5. National Institute of Standards and Technology, SP 800-86, Guide to Integrating Forensic Techniques into Incident Response. csrc.nist.gov
  6. Scientific Working Group on Digital Evidence, published best practice documents. swgde.org
  7. Microsoft, eDiscovery and Purview documentation for holds, searches and exports. learn.microsoft.com
  8. Google, Google Vault help documentation for retention, holds, searches and exports. support.google.com
  9. The Sedona Conference, Principles Addressing Electronic Document Production. thesedonaconference.org
  10. EDRM, the Electronic Discovery Reference Model framework. edrm.net

#DigitalForensics #ComputerForensics #CellPhoneForensics #ExpertWitness #DigitalForensicExperts #EliteDigitalForensics #ForensicInvestigation #EDiscovery #EDiscoveryServices #ESI #ElectronicDiscovery #ChainOfCustody #ForensicCollection #LitigationSupport #ESIPreservation

This content is for educational and informational purposes only and does not constitute legal advice. Elite Digital Forensics provides independent digital forensic and E-Discovery services and expert witness testimony; we do not provide legal representation. Every case is fact specific; outcomes depend on the evidence, jurisdiction, and counsel. Retain qualified legal counsel for advice about your matter.

Assistant Icon Elite Digital Forensics Assistant
πŸ‘‹ Live Chat Now!
Free Virtual Consultation 24/7
Chat Now!

By submitting this form, you consent to be contacted by email, text, or phone. Your information is kept secure and confidential. Reply Stop to opt out at anytime.Β 

IMPORTANT: Please remember to check your spam or junk folder