Digital Forensic Investigation: How Deleted Evidence Gets Recovered and Used in Indian Courts
Key Takeaways:
- Digital forensic investigation is the structured process of identifying, preserving, analyzing, and presenting electronic evidence in a legally admissible format
- India's legal framework changed fundamentally in July 2024: the BNS, BNSS, and BSA replaced the IPC, CrPC, and Indian Evidence Act respectively
- Under the Bharatiya Sakshya Adhiniyam 2023 (BSA), Section 63 replaces the old Section 65B of the Indian Evidence Act and now expressly covers communication devices alongside computers
- The BNSS 2023 Section 176(3) makes forensic expert attendance at crime scenes mandatory for all offences punishable with seven years or more
- BNSS Section 105 requires every search and seizure to be recorded through audio-video electronic means and forwarded to a Magistrate without delay
- The six stages of digital forensics are identification, preservation, collection, examination, analysis, and reporting
- Types of digital evidence include file system data, network logs, metadata, volatile memory, mobile device data, and cloud records
- Key tools used by investigators include Autopsy, FTK, EnCase, Cellebrite, Wireshark, and Volatility
Your bank sent you a message at 3 AM. Rs 4.7 lakh had left your account in four transactions across 11 minutes. By the time you called the helpline, the money was already moving through three mule accounts.
You filed a complaint at the cyber crime police station. The officer took your statement and told you to wait.
Three months later, you got a call saying the case had been closed. Insufficient digital evidence.
That outcome is not inevitable. But it is common, and it is almost always traceable to one of two failures: either no forensic investigation was conducted at all, or the investigation that was conducted produced evidence that could not survive scrutiny in court.
Digital forensic investigation is the discipline that determines which of those two outcomes you get. Since July 1, 2024, the legal rules governing how that evidence is collected, certified, and admitted in Indian courts have changed significantly. The Bharatiya Nyaya Sanhita (BNS), the Bharatiya Nagarik Suraksha Sanhita (BNSS), and the Bharatiya Sakshya Adhiniyam (BSA) have replaced the Indian Penal Code, the Code of Criminal Procedure, and the Indian Evidence Act. Every advocate, investigator, and cyber crime victim in India is now operating under a new framework, whether or not they know it.
What Is Digital Forensic Investigation?
Digital forensic investigation is the structured, legally defensible process of identifying, preserving, collecting, examining, analyzing, and presenting electronic evidence.
A forensic investigation is not someone opening a laptop and looking for suspicious files. It is a chain of custody process, governed by documented procedures, that ensures every piece of evidence collected can be traced back to its source, demonstrated to be unaltered, and presented in a format a court will accept.
India's legal framework for electronic evidence now rests on three new statutes that came into force on July 1, 2024.
The Bharatiya Sakshya Adhiniyam (BSA) 2023 governs the admissibility of evidence in court, replacing the Indian Evidence Act 1872. Section 61 of the BSA establishes that no electronic or digital record can be denied admissibility on the ground that it is an electronic or digital record. Section 63, which replaces the former Section 65B of the Indian Evidence Act, sets out the conditions under which electronic records are admissible. Critically, Section 63 expressly covers not just computers but "communication devices," a term broad enough to encompass smartphones, tablets, and any network-connected device. A Section 63 certificate must now be submitted at each instance where an electronic record is produced before a court.
The Bharatiya Nagarik Suraksha Sanhita (BNSS) 2023 governs criminal procedure, replacing the CrPC. Section 105 mandates that every search and seizure be recorded through audio-video electronic means, preferably a mobile phone, with the recording forwarded to a Magistrate without delay. Section 176(3) creates a mandatory forensic expert requirement: for any offence punishable with seven years or more, the officer in charge of the police station must cause a forensic expert to visit the crime scene to collect forensic evidence, and must cause the entire process to be videographed on a mobile phone or other electronic device.
The Bharatiya Nyaya Sanhita (BNS) 2023 replaces the Indian Penal Code and restructures the offence provisions most commonly invoked in cyber crime cases. Section 318 covers cheating, Section 319 covers cheating by personation, Section 336 governs forgery, and Section 340 specifically addresses forged electronic records used as genuine documents. Section 111 covers organised crime, which now expressly applies to cyber crime syndicates operating through structured networks.
The Information Technology Act 2000 continues to operate alongside these new statutes. Section 43 covers damage to computer systems, Section 66 covers computer-related offences, Section 66C criminalizes identity theft using electronic means with punishment up to three years and a fine of up to Rs 1 lakh, and Section 66D covers cheating by personation through any communication device.
Types of Digital Evidence
Digital evidence is any electronically stored information that can be used to prove or disprove facts in a legal proceeding. Under Section 2(d) of the BSA, "document" now explicitly includes electronic records on emails, server logs, documents on computers, laptops or smartphones, messages, websites, locational evidence, and voice mail messages stored on digital devices. This definition is broader than what the Indian Evidence Act 1872 originally contemplated and directly extends documentary evidence protections to the full range of digital data a forensic investigator might collect.
File System Evidence
This is the most commonly understood category: documents, spreadsheets, images, video files, audio recordings, emails, and application data stored on a device's hard drive or solid-state storage. File system evidence includes not just existing files but deleted files. When a file is deleted from most operating systems, the data is not immediately overwritten. The file system record that points to it is removed, making the space available for reuse, but the underlying data often persists until new data physically overwrites the same storage sectors. Forensic tools can recover this data during the examination window before it is overwritten.
Metadata
Metadata is data about data. A photograph contains metadata recording when it was taken, on what device, at what GPS coordinates if location was enabled, and what software was used to edit it. A Word document contains metadata showing who created it, when it was last modified, and what edits were made. An email header contains metadata showing every server the message passed through between sender and recipient, with timestamps at each hop. Metadata is often more valuable than the content it describes, because it is harder to forge consistently and is generated automatically without the user's awareness.
Network and Log Data
Network evidence includes internet connection logs from ISPs, router logs, server access logs, firewall logs, and DNS query records. This category is particularly important in cases involving hacking, phishing, unauthorized access, and online fraud. Network logs establish which IP address connected to a system at what time, what actions were taken, and through what path the connection traveled. Under the BNSS, ISP logs can be obtained by law enforcement and by courts through summons to service providers. Retention periods vary by provider and are not standardized, creating a time-sensitive aspect to collection.
Volatile Memory (RAM)
RAM is the working memory of a running device. Unlike storage drives, RAM is erased when the device powers off. Volatile memory contains running processes, open network connections, decryption keys for encrypted files, logged-in session tokens, clipboard contents, and other transient data that exists only while the device is active. Capturing RAM requires specialized acquisition techniques performed on a live system. This is one of the most technically demanding aspects of digital forensics and one of the areas where evidence is most frequently lost, because investigators or victims power off devices before RAM capture is completed.
Mobile Device Evidence
Mobile devices present a forensically distinct category. They contain call records, SMS and messaging app data, app usage logs, GPS location history, photographs with embedded location metadata, browser history, contact lists, synchronized account data, and deleted content recoverable through forensic extraction. Under the BSA's broader definition of "communication device," mobile phone data now falls squarely within the documentary evidence framework, making proper extraction methodology directly relevant to admissibility. Android and iOS devices have different extraction methodologies, and specialized court orders may be required depending on the device state.
Cloud and Account Evidence
Cloud evidence includes data stored on remote servers: email archives, cloud storage files, messaging platform records, social media activity logs, payment transaction records, and authentication logs from online services. Under the BNSS, Section 94 empowers courts to issue production summons to any person or entity in possession of documents or electronic records relevant to an investigation. For Indian-headquartered platforms, a police demand or court order is the standard mechanism. For US-headquartered platforms like Google, Meta, or Microsoft, Mutual Legal Assistance Treaty requests are required, which are slower and less predictable.
The Six Stages of Digital Forensic Investigation
Every credible digital forensic investigation follows a structured methodology that mirrors the scientific method: repeatable, documented, and defensible.
Stage 1: Identification
The investigation begins by identifying what devices, accounts, systems, or data sources may contain relevant evidence. This requires scoping the incident: the nature of the crime, the time period involved, the technology used, and the forensic objectives. In a financial fraud case under BNS Section 318, identification might cover the victim's device, the fraudster's device if known, transaction logs from the bank's servers, and phone records. In an identity theft case under IT Act Section 66C, it might cover account access logs, device fingerprints, and location data. Identification is where the investigation's strategy is set, and a poorly scoped identification phase means evidence is missed at every subsequent stage.
Stage 2: Preservation
Before any analysis begins, evidence must be preserved in its current state. Preservation means ensuring that the act of investigation does not alter the evidence being investigated. For digital storage media, preservation involves creating a forensic image, a bit-for-bit copy of the entire storage device including all sectors, whether they appear empty or not. The original device is then sealed and stored without further access. Under BNSS Section 105, any search and seizure conducted by police must itself be recorded through audio-video electronic means and forwarded to the relevant Magistrate. This requirement creates a procedural record of the seizure that courts can verify against the chain of custody log.
Stage 3: Collection
Collection is the physical or logical acquisition of evidence. For storage devices, this means creating verified forensic images using write-blocking hardware that prevents any writes to the original device during the imaging process. For volatile memory, it means RAM capture while the device is live. For network logs, it means obtaining records from ISPs and service providers through appropriate legal process under the BNSS.
Every acquisition must be hash-verified. A cryptographic hash value, typically SHA-256 or MD5, is calculated for the acquired image immediately after acquisition and recorded. This hash value is a unique fingerprint of the data at that moment. If the image is later accused of having been tampered with, the investigator recalculates the hash and demonstrates that it matches the original recorded value, proving the data has not changed. This hash verification forms a critical part of the BSA Section 63 certificate process.
Stage 4: Examination
Examination is the process of extracting relevant data from acquired evidence. Forensic examiners use specialized tools to parse file systems, recover deleted files, extract metadata, decode application data formats, and identify artifacts left by user activity. Under BNSS Section 176(3), the State Government must notify a date within five years from the statute's commencement from which forensic experts will be mandated at crime scenes for all offences carrying seven years or more. Until that notification is issued in each state, the mandate is aspirational rather than immediately enforceable, but it establishes the direction in which Indian forensic practice is moving.
Stage 5: Analysis
Analysis is where extracted data is interpreted to reconstruct what happened and when. Timeline analysis places events in chronological sequence across multiple data sources. Link analysis maps relationships between identifiers: phone numbers, email addresses, IP addresses, usernames, and financial accounts. Artifact correlation identifies connections between items found on different devices or from different sources pointing toward the same actor or event. In cases invoking BNS Section 111 on organised crime, which can cover structured cyber fraud syndicates operating through multiple layers of mule accounts, analysis must demonstrate the network relationships between participants in a way that satisfies the statutory definition.
Stage 6: Reporting
The forensic report is the investigation's output. It must document every step of the investigation, every tool used, every finding, the methodology applied to reach conclusions, and the limitations of the analysis. Under BSA Section 63(4), a certificate must be submitted alongside the electronic record at each instance where it is produced before a court. This certificate must identify the electronic record, describe the manner in which it was produced, specify the device involved, and address the conditions set out in Section 63(2). The certificate must be signed by a person in charge of the relevant computer or communication device, or the management of the relevant activities, and constitutes expert evidence of any matter stated in it.
Key Tools Used in Digital Forensic Investigations
Digital forensic investigators use a combination of commercial, open-source, and proprietary tools depending on the investigation type and the device category being examined.
Autopsy is an open-source forensic platform providing a graphical interface for analyzing disk images. It supports file recovery, keyword searching, metadata extraction, timeline analysis, and integration with a range of plugins. It is widely used by law enforcement and private forensic examiners globally.
Forensic Toolkit (FTK) from AccessData is a commercial platform used extensively in law enforcement contexts. It is known for speed in processing large data sets and its integration with FTK Imager, which produces court-accepted forensic images with automatic hash verification.
EnCase from OpenText is one of the longest-established commercial forensic platforms and is widely accepted in Indian legal proceedings. EnCase is used for disk imaging, file recovery, email analysis, and report generation. Its evidence files (.E01 format) are a recognized standard for forensic images.
Cellebrite UFED is the industry standard for mobile device forensic extraction. It supports a wide range of Android and iOS devices, extracts deleted messages and application data, and produces reports formatted for legal proceedings. Law enforcement agencies in India including the Central Forensic Science Laboratory use Cellebrite-based mobile extraction. Given the BSA's express extension of documentary evidence rules to communication devices, Cellebrite-generated extractions are now directly within the scope of Section 63 certification requirements.
Wireshark is an open-source network protocol analyzer used for capturing and examining network traffic. In cases involving unauthorized network access, man-in-the-middle attacks, and data interception, Wireshark captures provide packet-level evidence of what traversed a network and when.
Volatility is an open-source RAM analysis framework used to examine memory captures from live systems. It extracts running processes, network connections, registry hives, and other volatile artifacts from memory images, providing evidence that is otherwise unavailable after a device is powered off.
The New Legal Framework: What Changed on July 1, 2024
The three new codes that came into force on July 1, 2024, changed the legal environment for digital forensics in ways that practitioners are still absorbing.
BSA Section 63 versus old Section 65B
The old Section 65B of the Indian Evidence Act was the source of more cyber crime evidence disputes than any other provision in Indian law. Courts, including the Supreme Court in Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal (2020), spent years clarifying when the certificate was mandatory and who could issue it.
BSA Section 63 retains the certificate requirement but makes two significant changes. First, it expressly includes "communication device" as a source of computer output, alongside standalone computers, computer systems, computer networks, computer resources, and intermediaries. This means smartphone-extracted evidence, previously contested as to whether Section 65B applied, is now squarely within the statutory framework. Second, the certificate must be submitted "at each instance" where the electronic record is produced for admission, removing ambiguity about when the certificate was required during proceedings.
BNSS Section 176(3): The Forensic Expert Mandate
This is the most operationally significant change for cyber crime investigation in India. Section 176(3) of the BNSS provides that for any offence punishable with seven years or more, the officer in charge of the police station must cause a forensic expert to visit the crime scene to collect forensic evidence, and must cause the process to be videographed on a mobile phone or other electronic device.
Most cyber crimes prosecuted under the IT Act carry penalties of seven years or more. Financial fraud at scale, identity theft, hacking of critical systems, and cyber terrorism all fall within this threshold. The BNSS forensic mandate means that for these cases, forensic expert involvement is not a discretionary good practice. It is a statutory obligation on the investigating officer, enforceable through supervisory mechanisms and challenge in court.
The practical constraint is the notification requirement. Each State Government must notify the date from which the forensic mandate becomes operative in that state, within five years of the statute's commencement. Until a state notifies, the obligation is pending. Victims and advocates in states where the notification has not yet been issued should document that request in their complaint and follow up formally.
BNSS Section 105: Mandatory Audio-Video Recording of Search and Seizure
Section 105 requires that the entire process of conducting a search of a place or taking possession of property, including preparation of the seizure list and signing by witnesses, be recorded through audio-video electronic means, preferably a mobile phone. The recording must be forwarded to the District Magistrate, Sub-divisional Magistrate, or Judicial Magistrate of the first class without delay.
For cyber crime victims, this provision creates an accountability mechanism. If the investigating officer conducted a search of a suspect's premises and seized digital devices, the victim or their advocate can seek the audio-video recording through the relevant Magistrate. If no recording was made, that gap is itself a procedural irregularity that can be raised in any subsequent challenge to the investigation's integrity.
BNS Provisions for Cyber Crime Offences
The BNS restructures the substantive offences most commonly charged in cyber crime cases.
Section 318 on cheating replaces IPC Section 420. Section 319 on cheating by personation replaces IPC Sections 416 and 419. A person is said to cheat by personation under Section 319 if they cheat by pretending to be some other person, by substituting one person for another, or by representing that any person is someone other than they really are. The offence applies whether the person personated is real or imaginary. Punishment for cheating by personation is imprisonment up to seven years plus fine, an increase from the IPC regime.
Section 336 on forgery and Section 340 on using a forged electronic record as genuine are particularly relevant to cases involving fabricated transaction records, manipulated screenshots, spoofed emails, and altered digital documents. Where a fraudster creates a fake payment confirmation or alters a banking document to deceive a victim, Sections 336 and 340 of the BNS provide the substantive charge alongside IT Act provisions.
Section 111 on organised crime is now available for cyber fraud syndicates operating through structured networks of recruiters, mule account handlers, callers, and withdrawal agents. For cases involving call-centre fraud, SIM-swapping rings, or coordinated financial fraud networks, Section 111 opens higher sentencing ranges and enables investigation of the full organisational structure rather than only the individuals physically caught.
Why Digital Forensic Evidence Still Fails in Indian Courts
The new laws have improved the framework. They have not eliminated the failure modes that cause cases to collapse.
BSA Section 63 non-compliance is the new version of the old Section 65B problem. The certificate must now be submitted at each instance of production, not just once at trial. Investigators and advocates who treat the certificate as a one-time formality will find evidence excluded at interim stages of proceedings.
Broken chain of custody remains the second most common failure. Every person who handles evidence, every transfer of custody, and every change of location must be recorded in a chain of custody log produced in court. The BNSS Section 105 audio-video recording of seizure creates one layer of this record, but it does not substitute for the full chain of custody documentation required from seizure to court presentation.
Write contamination occurs when investigators access a device directly without first creating a forensic image using write-blocking hardware. Any access to a live system, even simply switching it on, writes new data to the storage medium and alters timestamps and file system records. Evidence collected from a contaminated device is vulnerable to challenge on grounds that the collection process itself altered the evidence.
Tool validation gaps arise when forensic tools have not been validated for the specific device type, operating system version, or application format they are applied to. Under the BSA Section 63 certificate framework, the certifying person must be able to describe the manner in which the electronic record was produced, which requires knowing what tools were used and being able to account for their reliability.
State notification gaps for forensic mandates are a new failure mode created by the BNSS. In states that have not yet notified the Section 176(3) forensic expert mandate, investigators may not deploy forensic experts even in cases where they are now expected. Victims in those states face the same inadequate investigation risk they faced under the CrPC, with the additional complication of a statutory promise that has not yet been delivered.
Frequently Asked Questions
Q: What replaced Section 65B of the Indian Evidence Act for digital forensics?
A: Section 65B has been replaced by Section 63 of the Bharatiya Sakshya Adhiniyam (BSA) 2023, which came into force on July 1, 2024. Section 63 retains the same core structure: electronic records are admissible as documentary evidence if the conditions in the section are met, and a certificate must be submitted by a responsible person identifying the record, the device, and confirming the system was operating properly. The key additions are that Section 63 expressly covers communication devices alongside computers, and the certificate must be submitted at each instance of production, not just at one stage of proceedings.
Q: Does the BNSS 2023 require forensic experts at every cyber crime scene?
A: Section 176(3) of the BNSS requires a forensic expert to visit the crime scene and cause videography of the process for any offence punishable with seven years or more. However, this obligation becomes operative in each state only from the date notified by that State Government, within five years of the statute's commencement in July 2024. Until your state issues its notification, the mandate is pending. Victims should document their request for forensic investigation formally in their complaint, and advocates can use the BNSS provision to press investigating officers on why forensic expertise was or was not deployed.
Q: What BNS sections apply to online fraud and identity theft?
A: The primary BNS provisions are Section 318 (cheating, replacing IPC 420), Section 319 (cheating by personation, replacing IPC 416 and 419), Section 336 (forgery), and Section 340 (using a forged electronic record as genuine). These operate alongside the IT Act: Section 66C covers identity theft using electronic means with punishment up to three years and Rs 1 lakh fine, and Section 66D covers cheating by personation through any communication device. In organised fraud cases involving structured syndicates, BNS Section 111 on organised crime may also be invoked.
Q: If I am a victim of cyber crime, how do I make sure digital evidence is preserved?
A: Act within days, not weeks. Contact your bank or service provider immediately to request log preservation before retention periods expire. Do not switch off, reset, or factory restore any device that may contain evidence. Take screenshots with timestamps of any fraudulent communications. File your complaint at cybercrime.gov.in, specifically request that the investigating officer seek BNSS production summons for ISP logs and server records, and ask whether the Section 176(3) forensic expert mandate has been notified in your state. Consulting a cyber law advocate who can apply to court for evidence preservation orders is advisable in cases involving significant loss.
Q: What is the BSA Section 63 certificate and who must sign it?
A: The BSA Section 63 certificate is a document that must accompany every electronic record produced as evidence in court. It identifies the electronic record, describes how it was produced, specifies the device or system involved, and confirms that the system was functioning properly during the period in question. It must be signed by a person in charge of the relevant computer or communication device, or the management of the relevant activities. In practice, this means the bank's IT head for banking transaction logs, the ISP's technical officer for connection logs, or the forensic investigator who acquired and examined the device. The certificate constitutes expert evidence of any matter it contains, which means it can itself be challenged by opposing counsel.
Q: Can private forensic experts be appointed under the new BNSS framework?
A: Yes. The BNSS retains provisions for expert witnesses, and parties to criminal proceedings can engage private forensic experts to examine evidence and produce reports. The expert's findings are evaluated by the court alongside other evidence. In cases where police investigation has been inadequate or where the victim obtained device or account evidence independently before the police acted, a private forensic expert's report produced with full BSA Section 63 certification can be introduced through appropriate court process. A cyber law advocate can advise on the correct procedural mechanism for the jurisdiction in which the case is being heard.