Evidence First · Vol. 1 · 2027 Edition · Forthcoming

EVIDENCE FIRST.
DECISIONS FOLLOW.

A field decision system for actions that can change the evidence. Evidence First is built for the point of evidence handling: observe what is actually present, compare viable actions, make gain, loss, footprint, risk and reversibility explicit, then decide and document.

A reversible action buys options.An irreversible action spends them.
Cover of Evidence First Vol. 1: Computer — Computer First Response & Forensic Acquisition
61Core Field Cards
33State Maps
174Pages
A0–A4Field Forms
Forthcoming2027 Edition

What it does

Built for the moment before the next action changes the evidence.

Evidence First does not begin with a preferred tool, command, artifact or vendor workflow. It begins with the evidentiary state in front of the operator and structures the decision that follows: what can still be preserved, what may be lost, what footprint each action introduces, what risks follow, and whether the previous state can realistically be reconstructed.

01Observe before intervention
02Compare realistic alternatives
03Preserve options before spending them
04Document the reason for the choice
A02 · D1

Multiple Live Devices

FIRST RESPONSE
SITUATION

Two or more in-scope general-purpose computers are live at the same scene, but time, personnel, or acquisition capacity prevents treating all of them simultaneously.

Which computer must be handled first to avoid spending the most fragile or least reproducible evidence state?
OBSERVEDestructive activity?Unique unlocked state?Instability or imminent state loss?
OPTIONS & CONSEQUENCESPrioritize fragile stateParallelize with trained operatorsAvoid convenience-first ordering
DECIDEDOCUMENTGAIN · LOSS · FOOTPRINT · RISK · REVERSIBILITY

Positioning

A field decision system, not a survey course.

The series is deliberately narrower than a general digital-forensics textbook and deliberately more durable than a tool manual. Its job is to support defensible action at the point where handling, acquisition, access and preservation choices can alter the evidence.

Point-of-action

Start where the operator actually stands: in front of a device or evidence state that may change as soon as action begins.

Consequence-first

Compare gain, loss, footprint, risk and reversibility before selecting the next action.

Tool-independent

Keep the decision logic useful even when products, interfaces and acquisition capabilities change.

The method

One decision grammar across every domain.

The canonical sequence remains stable across the series. Domain-specific differences change the decision, not the grammar used to evaluate it.

01SCOPE
02OBSERVE
03OPTIONS
04GAIN
05LOSS
06FOOTPRINT
07RISK
08REVERSIBILITY
09DECIDE
10DOCUMENT

The canonical series

Six domains. One home volume for each decision.

Vol. 1 is the forthcoming 2027 edition and the canonical entry point to the series. Vols. 2–6 are in production and retain the same Evidence First grammar while owning distinct evidence regimes.

VOL. 01

COMPUTER

Computer First Response & Forensic Acquisition

Forthcoming · 2027 Edition
VOL. 02

MOBILE DEVICES

Mobile First Response & Forensic Acquisition

In production
VOL. 03

NETWORK & REMOTE INFRASTRUCTURE

Network First Response & Evidence Collection

In production
VOL. 04

CLOUD & SAAS

Cloud First Response & Evidence Collection

In production
VOL. 05

EMBEDDED & IOT DEVICES

Device First Response & Forensic Acquisition

In production
VOL. 06

COMPLEX SCENES

Cross-Domain First Response & Evidence Coordination

In production

Maintained source base

The printed guide stays stable. The companion stays current.

Edition-relevant standards, forensic guidance and platform documentation are tracked in the web companion. Source status is explicit: final, draft, archived and historical material are not treated as equivalent.

ISO/IECNISTSWGDEPlatform documentation

Card Registry

Canonical public identifiers for cards in the 2027 edition.

Browse cards →

Updates

Edition status, errata and decision-relevant maintenance.

View updates →

About the author

Lello Molinario

Works across digital investigations, cybersecurity, and digital forensics, with a focus on the operational handling of digital evidence. His work combines field practice with academic study in computer engineering, cybersecurity, and artificial intelligence.

Evidence First grew from a recurring field problem:

an intervention can preserve evidence or access while consuming options that may not be recoverable later.