- Nationwide Digital Forensic & Cyber Investigation Services
Custodians are rarely in the same city as the lab, and few businesses can hand over a working laptop for a week. Remote collection solves both problems. An Elite Digital Forensics examiner acquires the computer, mailbox, cloud account or mobile device over an encrypted connection, hashes the data at the source, verifies it on receipt, and documents the same chain of custody a lab acquisition would produce.
Updated August 2026 · Reviewed by Elite Digital Forensics examiners · Remote and on site service nationwide
Quick answer. Remote E-Discovery collection is the acquisition of electronically stored information from a device or account in another location, performed under examiner supervision over an encrypted connection. A collection agent or supervised session captures a full or targeted image, hash values are calculated at the source and verified on receipt, and the process is documented in a chain of custody record. For most computer, email and cloud sources it is forensically equivalent to an in person acquisition, is faster to schedule, and avoids shipping devices or taking custodians offline for days.
| Question | Short answer |
|---|---|
| What is remote collection? | Examiner supervised forensic acquisition of a device or account over an encrypted connection. |
| Is it forensically defensible? | Yes. Hashing at the source, verification on receipt and a documented chain of custody. |
| Do we ship the laptop? | No. The device stays with the custodian and remains usable outside the collection window. |
| What can be collected remotely? | Windows and macOS computers, mailboxes, cloud drives, collaboration tools and many mobile sources. |
| What cannot? | Damaged or encrypted devices needing lab work, some full physical phone images and air gapped systems. |
| How long does it take? | Targeted collections often finish in hours; full images depend on volume and upload bandwidth. |
| Does the custodian need technical skill? | No. They install a provided agent or join a supervised session and follow instructions. |
| What documentation is produced? | Acquisition worksheet, hash manifest, activity log and chain of custody record. |
Remote collection replaces the physical trip, not the forensic method. The examiner still controls scope, tooling, hashing and documentation. What changes is how the examiner reaches the data.
The custodian receives a link to a small collection utility with a one time credential. The examiner defines the scope, whether that is a full disk image or specific paths, mail stores, user profiles, date ranges and file types. The utility reads the source without writing to it, hashes each item or the entire image, and uploads to an encrypted evidence endpoint. The examiner monitors progress, verifies hashes on receipt and removes the utility when the collection is complete.
Where an agent cannot be installed, the examiner joins a screen shared session and directs the acquisition step by step while recording the session. This approach is common on tightly managed corporate endpoints and on systems where a security team requires visibility into every action taken.
Cloud sources are collected through native administrative and legal hold interfaces rather than through the endpoint. Microsoft 365 and Google Workspace expose export mechanisms, hold capabilities and audit logs that preserve server side metadata. Because these interfaces are reached over the internet by design, cloud collection is inherently remote.
Many mobile matters are handled with an encrypted backup collection performed in a supervised session, or with a prepaid, tracked shipping kit when a deeper extraction is required. Where a full physical extraction is necessary, the device generally has to reach an examiner in person.
Opposing counsel occasionally argues that a remote collection is inferior by definition. The response is technical and documented: the hash recorded at the source matches the hash verified in the evidence environment, the acquisition log shows what was read, and the examiner who supervised the process can testify. That record is often stronger than a shipped drive whose contents were copied by internal staff before it left the building.
| Source | Typical remote scope | Notes |
|---|---|---|
| Windows laptops and desktops | Full disk image or targeted profile, mail store and artifact collection | Registry, event logs, LNK, shellbag and USB artifacts included on request |
| macOS computers | Full or targeted collection of user data, mail and system artifacts | Full disk access and, on Apple silicon, an administrator credential are required |
| Microsoft 365 | Mailbox, OneDrive, SharePoint and Teams content plus unified audit log | Holds can be applied before export |
| Google Workspace | Gmail, Drive, Chat and Calendar via Vault, plus admin audit logs | Vault retention and hold coverage are confirmed first |
| File servers and network storage | Targeted share collection with permissions and path preservation | Scheduled outside business hours where volume is large |
| Collaboration platforms | Slack, Teams, Box and Dropbox exports with membership and sharing records | Export capability depends on the licensed plan |
| Mobile devices | Encrypted backup or supervised logical extraction | Deeper extractions may require the device in hand |
A drive with mechanical failure or a phone with a broken board requires lab handling and, in some cases, chip level recovery.
Advanced extraction methods generally require the examiner to have possession of the handset.
Classified, industrial control and isolated environments frequently prohibit outbound connections entirely.
A multi terabyte image over a slow upload link can take longer than shipping an encrypted drive with tracking.
Some orders and neutral examiner protocols specify in person acquisition and witnessed handling.
Remote collection depends on custodian participation. Where cooperation is doubtful, on site acquisition removes the variable.
We tell counsel plainly when a matter calls for on site acquisition rather than pushing a remote workflow that will be criticized later.
Remote collection usually costs less than the equivalent on site engagement because there is no travel, no shipping and less business disruption. Cost is driven by the number of custodians, the number of sources per custodian, the volume acquired and whether the acquisition is full or targeted. Cloud collections are priced on volume and export complexity rather than travel.
| Factor | Effect on timeline |
|---|---|
| Targeted computer collection | Often complete within a few hours per custodian |
| Full disk image over remote connection | Driven by drive size and upload bandwidth, commonly overnight |
| Mailbox export | Hours for a single mailbox, longer for large or multi year archives |
| Cloud drive collection | Depends on file count and API throughput at the provider |
| Multiple custodians | Collected in parallel where bandwidth and licensing allow |
| Preservation only | Holds can usually be applied the same day, before collection is scheduled |
Where a duty to preserve has attached and the schedule is tight, preservation comes first. Holds and forensic preservation stop the clock on automatic deletion so collection can proceed in an orderly sequence rather than in a rush.
This page is part of the Elite Digital Forensics E-Discovery services hub. Related coverage:
We scope the matter with counsel, apply preservation where a duty has attached, then schedule remote acquisition around the custodian's working hours. The examiner controls scope and tooling, verifies hashes on receipt, and delivers an acquisition worksheet, hash manifest, activity log and chain of custody record. From there the collection moves into processing, review support or forensic analysis, and our examiners remain available to testify about how the data was acquired.
Elite Digital Forensics is an independent digital forensics firm providing nationwide E-Discovery services, computer and mobile device forensics, cloud and email investigations and expert witness testimony. Our examiners include former law enforcement forensic examiners and court qualified expert witnesses. We work for law firms on both sides of the docket, for corporations and in house legal departments, and for insurers. When retained through counsel, our work is generally treated as attorney work product prepared in anticipation of litigation.
For most computer, mailbox and cloud sources, yes. The forensic requirements are unchanged: read only acquisition, hash values calculated at the source and verified after transfer, an activity log of what was read, encryption in transit and at rest, and a written chain of custody. A qualified examiner supervises the acquisition and can testify to method and verification.
Usually not. The device stays with the custodian. A small collection utility or a supervised session is used to acquire the data, and the custodian can keep working outside the collection window. Shipping is reserved for damaged devices, deep mobile extractions and matters where a protocol requires physical possession.
No. The custodian installs a provided utility with a one time credential or joins a screen shared session. The examiner defines and controls the scope, monitors the acquisition and verifies the result. Instructions are written in plain language and support is available throughout the session.
Yes. macOS collection requires full disk access for the collection utility and, on Apple silicon systems, an administrator credential. Once access is granted, targeted or full acquisition proceeds with the same hashing and documentation used on Windows systems.
Yes, and it is often the first step. Litigation holds in Microsoft 365 or Google Vault can typically be applied the same day, which stops retention policies and user deletion from removing potentially relevant material while collection is scoped and scheduled.
Data is hashed at the source, encrypted in transit over an authenticated connection, and stored encrypted in an evidence environment with access restricted to assigned examiners. Access is logged. Hash values are recalculated on receipt and compared with the acquisition values before any processing begins.
Collections resume rather than restart. The utility tracks progress and continues from the interruption point, and the final verification step confirms the completed acquisition matches the source hash values. Interruptions are recorded in the acquisition log.
Often yes, through an encrypted backup or supervised logical extraction that captures messages, call logs, media and much app data. A full physical extraction, which reaches deeper into deleted content, generally requires an examiner to have the handset in hand.
#DigitalForensics #ComputerForensics #CellPhoneForensics #ExpertWitness #DigitalForensicExperts #EliteDigitalForensics #ForensicInvestigation #EDiscovery #EDiscoveryServices #ESI #ElectronicDiscovery #ChainOfCustody #ForensicCollection #LitigationSupport #ESIPreservation
This content is for educational and informational purposes only and does not constitute legal advice. Elite Digital Forensics provides independent digital forensic and E-Discovery services and expert witness testimony; we do not provide legal representation. Every case is fact specific; outcomes depend on the evidence, jurisdiction, and counsel. Retain qualified legal counsel for advice about your matter.
Elite Digital ForensicsΒ is a Professional Digital Forensics and Cyber Consulting Company that provides services nationwide.Β
Elite Digital Forensics Assistant
By submitting this form, you consent to be contacted by email, text, or phone. Your information is kept secure and confidential. Reply Stop to opt out at anytime.Β
IMPORTANT: Please remember to check your spam or junk folder
We use cookies for site functionality and, only with your permission, analytics and advertising. See our Privacy Policy for details. California residents have the right to Do Not Sell or Share My Personal Information.