Next Article in Journal
A Novel Classification Model for Suspicious Human Activities in Diverse Environments Using Fused Feature Block and Machine Vision Techniques
Previous Article in Journal
Dynamic Anthropomorphism and Artificial Empathy in Conversational Agents: A Wizard-of-Oz Experimental Evaluation
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

Designing and Validating a Forensic Evaluation Model for Selective Seizure Capabilities in Windows Forensic Tools

1
AbleSECU, Seoul 07788, Republic of Korea
2
Laboratory of Autonomous Vehicle and Block-Chain, Korean National Police University, Asan 31539, Republic of Korea
*
Author to whom correspondence should be addressed.
Digital 2026, 6(2), 29; https://doi.org/10.3390/digital6020029
Submission received: 20 January 2026 / Revised: 4 March 2026 / Accepted: 23 March 2026 / Published: 7 April 2026

Abstract

The increasing volume and complexity of digital evidence pose significant challenges to its lawful collection and admissibility, particularly in on-site investigative contexts. Selective seizure has emerged as a critical approach for minimizing unnecessary data acquisition while ensuring procedural legality, privacy protection, and investigative efficiency. However, despite its growing importance, systematic evaluation criteria for selective seizure capabilities in digital forensic tools remain underdeveloped. This study proposes a structured evaluation framework for assessing selective seizure functions in Windows-based forensic tools, with a focus on live-response environments. Essential selective seizure functions were identified and organized into three investigative phases—search, selection, and seizure—reflecting practical field procedures. Based on this framework, a dedicated evaluation dataset was constructed, and six representative portable forensic tools were empirically evaluated under a controlled Windows 10 (NTFS) environment simulating active system conditions. The experimental results demonstrate notable differences in tool capabilities across investigative phases. In the search phase, variations were observed in NTFS parsing and Windows artifact analysis, while the selection phase revealed disparities in file filtering, keyword search, encrypted file handling, and preview functions. In the seizure phase, only a subset of tools sufficiently supported evidence collection, integrity verification, and reporting requirements necessary for selective seizure. These findings highlight that no single tool uniformly satisfies all functional requirements, underscoring the need for context-dependent tool selection. The proposed framework and evaluation results provide practical guidance for digital forensic practitioners in selecting appropriate tools for selective seizure in field investigations. Moreover, this study contributes a reproducible methodological foundation for future research on selective seizure evaluation, supporting the development of more precise, proportionate, and legally robust digital evidence collection practices in Windows-based forensic investigations.

1. Introduction

In digital forensics, search and seizure procedures typically involve the copying or printing of digital data, except for physical storage media [1]. Despite the importance of selective seizures in investigations, research on the tools used during the process is lacking. Investigative agencies use forensic tools to search and seize storage media, and their legal admissibility depends on the ability of such tools to reliably perform selective seizures. However, digital forensic tools with selective seizure functions are yet to be developed, resulting in the insufficient implementation of relevant functionalities. An effective selective seizure function should offer the capability to extract and seize only digital information relevant to criminal suspicion, thereby minimizing unnecessary information, protecting privacy and human rights, ensuring compliance with laws, and enabling investigations that meet the required standards. In this study, selective seizure functions are identified, six digital forensic tools are selected, and a model is designed to evaluate the functions. Based on the model, a dataset is generated to test the capabilities of each tool. The evaluation criteria are designed based on the requirements for digital forensic tool verification from prior research, such as the “NIST CFTT verification items and domestic TTA standardization documents.” The experimental environment is deployed in Windows 10, which features a high domestic market share of 77.9% [2], and tools registered with the National Institute of Standards and Technology (NIST) are employed to support the portable, graphical user interface (GUI)-based system for the New Technology File System (NTFS) [3]. The experimental setup for evaluating the functions of Windows forensic tools employs two laptops running Windows 10 in a VMware Workstation Pro virtual environment to simulate active system conditions [4].
This study aims to simulate the search–selection–seizure procedure conducted during the on-site investigation phase in a Windows 10 (NTFS) environment, using a dedicated dataset and six digital forensic tools, and to evaluate each tool’s efficiency and practical applicability. To this end, we constructed a dataset for a three-phase test and designed an evaluation model. In the search phase, to reflect field conditions, the scope included the analysis of file system information and Windows logs related to file timestamps; however, artifacts from cloud services, messaging platforms, remote access programs, and virtualized environments were excluded from the study scope. In the selection phase, the tools were compared with a focus on capabilities for filtering and searching case-relevant files, while analyses of unallocated space and free space were excluded. In the seizure phase, the evaluation emphasized functions for creating and collecting logical images based on file-level acquisition, while physical imaging and memory acquisition were considered only as supplementary capabilities when necessary. Because this study is intended to support initial on-scene triage and rapid investigative decision-making, analyses centered on deleted-data recovery and file carving were intentionally excluded. Accordingly, the proposed framework can serve as comparable and reproducible performance indicators within Windows environments. However, as the experiments were conducted under specific conditions based on Windows 10 (NTFS), direct generalization to heterogeneous environments such as macOS/Linux and file systems such as APFS/EXT is limited.

2. Related Work

Lee Soyeon [5] argues that an independent analysis institution can operationalize selective seizure in digital evidence searches by separating investigative interests from forensic processing, thereby enhancing procedural legitimacy, privacy protection, and the objectivity of digital forensic outputs. Lee Hyunseok [6] examines how non-selective imaging and the removal of original storage media inevitably transfer large volumes of irrelevant information, increasing the risk that the initial electronic evidence warrant becomes functionally “general.” The study emphasizes the need for stricter substantive review of secondary warrants for unrelated information—especially by scrutinizing the legality of the search that produced the discovery and the fortuity of discovery—and calls for reconsidering current practices regarding where and against what object such warrants are executed. Lee Seoyeon [7] proposed a methodology for prioritizing and selecting digital evidence based on metadata similarity. By assuming diverse scenarios in which metadata may be altered and designing corresponding similarity computation and detection procedures, the study argued that the approach could help address limitations inherent in selective seizure and collection processes. Cheon Seongdeok [8] analyzed, through experiments, the technical and temporal constraints that arise in current procedures in order to improve the effectiveness of on-scene selective seizure and search. In particular, the study focused on issues such as keyword search time and the possibility of metadata modification and presented practicable improvement measures for field deployment. Oh Jungkyung [9] noted that, as the digital environment evolves, the minimum unit of selection is shifting from the file level to an “information unit.” On this premise, the study emphasized that such a shift may raise new issues regarding integrity and the proof of identity with the original and suggested the need for improvements in both field procedures and institutional frameworks. Heo Jeongeun [10] examined the possibility that, in practice, digital evidence seizure and search may be conducted in stages—“on-scene selective seizure → full duplication (seizure of a copy) → seizure of the original.” After analyzing the limitations of selective seizure, including privacy infringement risks and guarantees of participatory rights, the study proposed institutional and operational measures to enhance procedural transparency and efficiency. Kim Youngmi [11] reviewed the limitations and resulting issues in applying the principles of “on-scene” and “selective” approaches in the seizure and search of digital (electronic) evidence. With a focus on Article 106 (3) of the Criminal Procedure Act, the study discussed directions for ensuring institutional coherence, emphasizing technical and legal improvements, including the need for legislative amendment. Yoon and Lee [12] developed a system for the automated collection of crime-specific data from crime scenes and organized them by crime type. They presented an objective and standardized evidence collection method and analysis guidelines independent of the investigators’ skills. They further developed an initial response method for field use. Cho [13] empirically examined timestamp behaviors associated with file deletion in the Windows file system. The results show that upon deletion, the write, MFT modification, and access timestamps in the $STANDARD_INFORMATION attribute are updated simultaneously, whereas the three creation timestamps remain unchanged. Shin [14] examined the email search and seizure process employed at a crime scene and developed an effective tool for the detailed analysis of email attachments based on field conditions. Methods to efficiently conduct searches and seizures have been proposed, suggesting the requirement for field tools tailored to file characteristics, rather than focusing solely on the importance of post-search acquisition. Lee and Shin [15] reviewed general verification procedures for digital forensic tools and conducted performance evaluations using proposed verification items and functional requirements. Their findings revealed fragmented file recovery, file-type recognition, and the handling of Korean strings as areas requiring improvement. Ham and Joshua [16] compared the characteristics, development release cycles, and development patterns of digital forensic imaging tools and proposed methods to address maintenance vulnerabilities. Park et al. [17] proposed verification scenarios and datasets for partition-recovery tools and established the dependency of tool performance on their ability to recover data from damaged storage media. Quick and Choo [18] emphasized the storage of a plethora of personal information on digital devices. Based on advancements in digital forensic technologies, they proposed standard procedures aligned with legal frameworks to resolve conflicts between investigations and safeguard human rights. Digital forensic imaging techniques were applied to big data, and an approach for selecting key files and data, such as registries, emails, documents, spreadsheets, internet history, communications, log files, photos, and videos for imaging, was developed. The data volume of the original media was successfully reduced by 100 times. Furthermore, the method was applied to cases from the Australian Law Enforcement Agency, and the possibility of further data volume reduction was established, demonstrating the applicability of data reduction techniques for the selective seizure of digital forensic data. Kim et al. [19]. proposed a dataset for verifying Windows forensic tools by classifying Windows artifacts into two categories: time-related and behavior-based artifacts, as test requirements for digital forensic tool verification. Lee [20] designed a software quality evaluation model based on the ISO/IEC 9126 standard and evaluated the reliability, usability, efficiency, maintainability, and portability of digital forensic tools.
Internationally, the U.S. NIST, a federal agency in the Department of Commerce, tests the functionality, reliability, and consistency of digital forensic tools to provide tool verification information to law enforcement agencies, investigative bodies, and corporate security professionals [21]. Particularly, the CFReDS project provides datasets for testing digital forensic tools to enhance digital evidence analysis capabilities [22]. Additionally, the Digital Forensic Research Workshop (DFRWS) has researched digital forensic tools and techniques to conduct standardization studies [23]. In addition, Forensic Focus reviews forensic tools, conducts webinars, and hosts forums, thereby providing information related to cybercrime investigations. However, previous studies have either been conducted on Windows 10 or older versions or have not experimentally evaluated and verified digital forensic tools for selective seizures that can be deployed in the latest operating systems. Therefore, this experimental study is designed to reflect tool verification requirements according to recent changes in the technological environment. The selected evaluation items are categorized into individual test cases and tested in an environment that simulates selective seizure procedures.

3. Evaluation Model and Dataset Development

3.1. Evaluation Model Design

Various institutions worldwide produce numerous forensic images annually to compare and verify the proficiency and performance of various forensic tools [24,25]. However, the existing image analysis method has certain limitations; although the method is suitable for analyzing seized media, it is inadequate for selective seizure analysis. Moreover, the method is static, whereas actual seizures in the field require dynamic image analysis because the operating system actively runs and imposes various restrictions, such as the need for file-access permissions. Domestic forensic societies, universities, and other institutions have developed and used various datasets for digital forensic tool verification and expert qualifications. In Korea, professional competency assessment is also supported through qualification systems jointly operated by relevant organizations [26,27]. However, to test tools for domestic environments, an analytical method that reflects the requirements of field investigations, rather than relying solely on media seizures, is required [28,29]. Additionally, an environment that allows additional tools to be tested in the future is desirable. Instead of using an evaluation method based on image files, a dataset that can be tested in an actual field environment is crucial [30]. Furthermore, an evaluation model to test the functions of forensic tools is essential for ensuring technical accuracy and legal validity [31]. The tests should be conducted in accordance with the standards established by government agencies, academic research institutions, and international standardization organizations. In this study, the tests were conducted based on an evaluation procedure derived from the ISO/IEC standards for digital evidence handling and analysis [32,33]. Table 1 presents the image formats used in the test datasets by various institutions and prior studies.
Existing requirements for verification covered in prior research were collected and compiled by adopting the criteria for the digital forensic tool evaluation model. The digital forensic requirements are as follows: (1) file system verification requirements, (2) file search verification requirements, (3) file time-related source log analysis verification requirements, (4) application analysis verification requirements, (5) data deletion and hidden verification requirements, and (6) verification and report requirements (Table 2, Table 3, Table 4, Table 5 and Table 6).
This verification design method is the result of a digital forensic field response tool evaluation model design study, which addresses gaps in previous literature.
Previous studies have established evaluation content for digital forensic tools, and the requirements for selective seizure tools have been reflected in their designs. The requirements include:
  • Tools must be portable, field-ready, feature a GUI, and be easy to use.
  • Tools must include functions for collecting case-relevant files in the field.
  • Tools must be able to analyze various logs.
  • Tools should support result verification and reporting.
During selective seizures, the Windows file system should be searched, and the generated evidence must be verified. Once the search is complete, the Windows log information should be searched for files of interest, and those related to criminal allegations must be identified. Finally, relevant files must be collected, and a report should be generated. Accordingly, an evaluation model for the Windows forensic selective seizure tool was designed for this study, as shown in Figure 1.
The digital forensic process involves the following steps: 1. investigation preparation; 2. evidence acquisition, 3. transportation and storage, 4. investigation and analysis, and 5. report generation. In this study, a new evaluation model was developed for Windows-based selective seizure tools that considers field response criteria. To ensure comprehensive testing, detailed evidence image files representing diverse application environments were created. File integrity was verified to ensure that the content did not change after the analysis, considering the characteristics of the target tools. The evaluation involved comparing the analysis functions of the selected seizure tools across the three main phases and eight items, as listed in Table 7.

3.2. Evaluation Metrics Model Design

Selective seizure in digital forensic investigations requires not only functional support from forensic tools but also a systematic method for evaluating whether such tools adequately satisfy procedural, technical, and legal requirements. To address this need, this study formalizes the evaluation of selective seizure functions through a phase-based analytical model supported by quantitative expressions. The proposed evaluation model is structured according to the three procedural phases commonly observed in field investigations: search, selection, and seizure. Each phase reflects a distinct investigative objective—identifying relevant artifacts, narrowing the scope of evidence, and securely collecting admissible digital evidence. Rather than treating selective seizure as a monolithic process, this phased structure allows the functional capabilities of forensic tools to be examined in alignment with actual investigative workflows, provides a narrative explanation of the rules applied for calculating the Selective Seizure Capability Index (SSI), and presents a step-by-step expansion of the calculation results for each evaluated Windows forensic tool. First, the SSI calculation begins with symbol-based scoring. In the evaluation tables, each functional item is assessed using qualitative symbols. These symbols are systematically converted into numerical scores to enable quantitative analysis. Specifically, a symbol of O is assigned a score of 3, □ is assigned a score of 2, △ is assigned a score of 1, and — is assigned a score of 0. Accordingly, for each evaluation item i within an investigative phase p, the score of a tool T is defined as s_{p,i}(T) ∈ {3, 2, 1, 0}. Second, phase-level raw scores are calculated. For each investigative phase—search, select, and seizure—the raw score E_p(T) of a tool is obtained by summing the scores of all evaluation items belonging to that phase. Because the number of evaluation items differs across phases, raw scores alone cannot be compared directly. Third, to ensure fairness across phases, each phase-level raw score is normalized. The normalization is performed by dividing the raw score by the maximum possible score for that phase, which is defined as three times the number of evaluation items. As a result, the normalized phase score ranges between 0 and 1, representing the proportion of functional requirements satisfied by the tool within that phase. Fourth, the normalized phase scores are aggregated into a single SSI value through weighted summation. In this study, weights of 0.3 were assigned to the search and select phases, while a higher weight of 0.4 was assigned to the seizure phase to reflect its direct relevance to evidentiary integrity and admissibility. The resulting SSI value, therefore, represents the overall degree to which a tool supports selective seizure procedures.
For interpretation convenience, the final SSI values are also expressed as percentages by multiplying the normalized SSI by 100. In this study, the number of evaluation items and corresponding maximum scores were fixed as follows: the search phase consisted of 49 items with a maximum score of 147, the select phase consisted of 80 items with a maximum score of 240, and the seizure phase consisted of 10 symbol-based items with a maximum score of 30. Non-symbolic entries, such as time measurements or descriptive report formats, were excluded from the SSI calculation to maintain reproducibility. Based on these rules, Tool A achieved a low SSI value, primarily due to minimal support in the search and select phases, despite moderate performance in the seizure phase. Tool B demonstrated balanced performance across all phases, resulting in a moderate SSI. Tool C showed relatively strong performance in the select and seizure phases, which significantly contributed to its higher SSI. Tool D exhibited strong search and seizure capabilities but weaker select-phase support, leading to a mid-range SSI value. Tool E achieved the highest SSI, reflecting consistently strong performance across all three phases, particularly in search and seizure functions. In contrast, Tool F showed limited search and select capabilities and relied mainly on seizure-phase performance, resulting in a comparatively low SSI. Overall, this narrative calculation process demonstrates that the SSI is not a simple ranking score but a structured and transparent index derived from phase-specific functional performance. By integrating normalization and weighted aggregation, the SSI enables reproducible, fair, and procedurally aligned evaluation of Windows forensic tools in selective seizure scenarios. The proposed evaluation model is structured according to the three procedural phases commonly observed in field investigations: search, selection, and seizure. Each phase reflects a distinct investigative objective—identifying relevant artifacts, narrowing the scope of evidence, and securely collecting admissible digital evidence. Rather than treating selective seizure as a monolithic process, this phased structure allows the functional capabilities of forensic tools to be examined in alignment with actual investigative workflows. Let T denote a Windows-based forensic tool subject to evaluation, and let p ∈ {search, select, seizure} represent an investigative phase. The evaluation score of tool T at phase p is defined as:
E p T = i = 1 n p s p , i T
where n_p is the number of evaluation items associated with phase p, and s_{p,i}(T) denotes the score assigned to the i-th evaluation item. This formulation enables a structured aggregation of tool capabilities within each procedural stage, ensuring that individual functional elements are assessed systematically rather than anecdotally. To preserve the intuitive clarity of qualitative assessment while enabling quantitative comparison, this study maps the symbol-based evaluation scheme to a numerical scoring function. Specifically, the score s_{p,i}(T) is defined as follows:
  • s{p,i}(T) = 3 if the tool fully satisfies all verification criteria (O);
  • s{p,i}(T) = 2 if three or more criteria are satisfied (□);
  • s{p,i}(T) = 1 if criteria are partially satisfied with manual intervention (△);
  • s{p,i}(T) = 0 if the criteria are not satisfied (-).
This mapping allows qualitative judgments to be expressed in a reproducible and transparent manner, thereby reducing subjectivity and enhancing analytical rigor. At the same time, the original symbolic representation is retained in the result tables to maintain practical interpretability for forensic practitioners. While phase-specific evaluation scores provide detailed insights into tool performance, selective seizure in practice requires an integrated assessment that reflects procedural priorities. Accordingly, this study introduces the Selective Seizure Capability Index (SSI) as a composite measure of overall tool suitability:
S S I T = p \ i n   P w p E _ p ( T )
where P = {search, select, seizure} and w_p denotes the weight assigned to phase p, subject to the constraint that ∑_{p} w_p = 1. The weighting scheme allows the evaluation model to adapt to investigative contexts; for example, greater emphasis may be placed on the seizure phase due to its direct implications for evidentiary integrity and admissibility, while search and selection phases emphasize efficiency and proportionality. By integrating phase-based evaluation, symbol-to-score formalization, and weighted aggregation, the proposed model establishes a coherent and extensible framework for assessing selective seizure capabilities in Windows forensic tools. This formalization not only enhances the reproducibility of comparative evaluations but also provides a methodological foundation for future extensions, such as usability metrics, automation levels, or cross-platform adaptations. Table 8 presents the tools evaluated in this study.
To maintain objectivity and avoid bias toward specific products, the evaluation focused on functional comparison rather than individual tools. The evaluated tools, along with their version and release information, are presented in Table 8. The latest versions, as of 30 November 2023, were used in the evaluation. The evaluation results were expressed using four symbols, as listed in Table 9, with the recommended tools labeled Recommendation 1 (Tool Name*) and Recommendation 2 (Tool Name**).

3.3. Dataset Development

To simulate a typical investigative scenario, the experimental environment for evaluating selective seizure functions comprised two standard laptops (Intel i5-1035G4 CPU, 8 GB RAM, and 250 GB SSD) instead of high-performance systems. The environment included a laptop with Windows 10 64-bit installed on a VMware virtual machine. Detailed specifications are listed in Table 10. To simulate a typical investigative scenario, the experimental environment for evaluating selective seizure functions was configured using two standard laptops with identical specifications (Intel i5-1035G4 CPU, 8 GB RAM, 250 GB SSD), rather than high-performance systems. Repeated tests were conducted under the same hardware specifications on both laptops, and the results presented in the manuscript were derived from these repeated measurements. In addition, the experimental setup included a laptop environment in which Windows 10 (64-bit) was installed on a VMware virtual machine. Detailed specifications are provided in Table 10.
The method for evaluating selective seizure function comprised three phases: search, selection, and seizures. To minimize the number of steps required, the recovery phase was integrated into the file system and application analysis. Additionally, based on the previously described procedures, the evaluation components included NTFS analysis, Windows log analysis, information searches, and collection/extraction. The parameters tested in the VMware virtual machine are listed in Table 11.
The information on the image files created in the VMware test environment included name, size, and hash information. The test environment was configured to generate the data necessary for evaluating the tool’s performance, including partition damage, file deletion, BitLocker configuration, and file timestamp information from Windows logs. A logical image comprising 200,000 files was created to test the selective seizure performance of the tools. The details of the virtual machine disk (VMDK) dataset are presented in Table 12.
The test dataset used in the VMware environment was divided into three configurations: file system and Windows log analyses, file search, and collection and extraction. Additionally, as numerous files and substantial Windows log information were used, along with processes such as installation, creation, and deletion, four test environments were constructed. Each of the six tools was evaluated once, and the VMware snapshot functionality was used to ensure a consistent evaluation of the results. The experimental procedure, as illustrated in Figure 2, was implemented in the VMware environment on a laptop using a custom evaluation dataset that was saved as a VMDK image file for reuse.
The dataset employed to evaluate selective seizure functions enabled extensive testing of portable tools and yielded accurate results through four configurations of Windows functions. The dataset offered a key advantage of data from Koreans, thereby allowing tool verification for application to the domestic environment, supporting the Korean language.

4. Results and Discussion

4.1. Search Phase

4.1.1. NTFS Parsing

We conducted experiments using the following tools: Magnet Outrider (A), Autopsy (B), X-Ways (C), OSForensics Professional and Bootable Edition (D), DFAS Pro (E), and Belkasoft Triage (F). In the remainder of this paper, these tools are referred to as A, B, C, D, E, and F. The NTFS parsing ability of the tools was tested across eight functions, as listed in Table 13. Tool C demonstrated the best performance, followed by Tool B. However, none of the tools met all the requirements. For example, only Tool E recognized the BitLocker volume and supported key-input decryption, whereas Tool D supported the VBR (MBR) damage repair functionality. Additionally, Tools B and C supported the recovery of the deleted MFT (MBR) partitions. Tool B provided comprehensive support for analyzing $MFT entry headers, $Standard Information, $File Name, $Attribute, and $Date. Although Tool C met most evaluation requirements, Tool B proved valuable, as it provided substantial information concerning NTFS. The evaluation results listed in Table 13 indicated whether the tools accurately interpreted the file system and provided the necessary information.

4.1.2. File- and Folder Access Log Analysis

We evaluated the tools’ ability to analyze file and folder access logs across 10 evaluation items, as listed in Table 9. Tool E exhibited the best performance, followed by Tool D. In the link file analysis, Tool D provided comprehensive information, including the creation, modification, and access times for both the link and target files. However, Tool B provided some Korean file names as garbled characters, indicating unoptimized tool behavior for Korean and the requirement of a code page change function for proper display. Notably, only Tool E supported Windows.edb, $Logfile, and UsnJrnl, which contained critical information related to document and file activities, suggesting that the functionality of the other tools required improvements. Furthermore, analyzing folder access logs was essential for confirming the evidence related to a case and tracing deleted information. The evaluation results, as listed in Table 14, indicated the importance of data activity analysis, which can be used to identify meaningful information and behaviors through prior investigations and evidence.

4.1.3. Application Execution Log Analysis

The tool’s ability to analyze application execution logs focused on four key areas, as listed in Table 10. Tool E performed the best, followed by Tool D. The results indicated that all tools supported the prefetch analysis, but Tool D did not support the SRUMDB analysis. Starting with Windows 10, log checking for application compatibility in the cache and DB information was added. Although the logs provided valuable forensic insight, our evaluation revealed that some tools required improvements. Specifically, Tool B required improvements in Gram-execution log analysis, and Tool D required improvements in SRUMDB analysis. The evaluation results, as presented in Table 15, indicated the capabilities of the tools for analyzing application execution activities, which could be used to determine the time and order of frequently used applications, detect data deletion or anti-forensic activities, and analyze application execution behaviors.

4.1.4. Data-Transmission Log Analysis

The tool’s ability to analyze data-transmission logs focused on six areas, as listed in Table 16. Tool C exhibited the best performance, followed by Tool E. However, Tool C necessitated manual analysis to verify the results, whereas Tool E enabled automatic analysis, offering greater usability. However, event logs related to external storage devices were not analyzed. Additionally, two tools supported the analysis of wired-network information, whereas two supported the analysis of the connection and disconnection records of external storage devices. In cases involving technology leaks, the history of the external storage device usage and network information required verification. Network information is categorized into wired and wireless, whereas external storage device information is analyzed using the registry, event logs, and Setup.API logs.

4.1.5. Internet Search Log Analysis

The tools’ ability to analyze internet search logs was evaluated using 18 items across three browsers (Google Chrome, Microsoft Edge, and Naver Whale). The results are listed in Table 17, where Tool E performed the best, followed by Tool B. Additionally, only Tool E supported the Whale browser analysis, whereas both Tools D and E supported the password analysis of the Edge. As the information stored in browsers is saved in database (DB) format, the tools should support DB analysis. Additionally, cache and cookie information were not configured in dedicated modules, making the analysis results difficult to interpret; thus, functionality improvements in these areas were necessary. As web browsers store data on internet activities and the interests of users, they provide crucial information for criminal investigations.

4.1.6. Suspicious Activity Log Analysis

The tool’s capability to analyze suspicious activity logs was tested across three EventLog items, as listed in Table 18. Evidently, Tool C performed the best, followed by Tools D and E, whereas the other tools did not support EventLog analysis. The logs recorded a wide range of information and were the key to forensic analysis. Therefore, the functionality of the tools for analyzing EventLogs required improvements. Tool C allowed manual analysis by installing an additional viewer; however, searching for the results required knowledge of the real log ID. Therefore, the ability to interpret EventLog analysis more easily required enhancement. Error and system-change information recorded in EventLogs was used for suspicious activity analysis and could be vital for identifying specific issues or proving criminal allegations.

4.2. Data Acquisition Phase

4.2.1. File and Folder Name Search

The tools’ capability to analyze file and folder name searches involved three items, as listed in Table 19. Tool C performed the best, followed by Tool E. Additionally, although most tools supported file name searches, they did not support folder name searches. Therefore, folder names and regular-expression search functionalities required improvements. In the NTFS, information on all files and directories, including records and file names, is stored in the MFT. The MFT record contains the $FILE_NAME attribute where the file name is stored.

4.2.2. Keyword Search

The evaluation of the tools’ capability to support keyword search involved 14 file extensions and five Korean word items, as listed in Table 20. Tool E performed the best, followed by Tool C. Additionally, Tool D supported the index search but not the keyword search, whereas Tools A and B detected only one and two keywords, respectively. Additionally, the functionality of the tools for analyzing Korean keywords and supporting a wider range of file extensions required improvement. A keyword search was crucial for efficiently finding important information within large datasets, accelerating the investigation, and quickly accessing evidence critical for solving the case.

4.2.3. File Header Classification

The file header classification performance of the tools was tested across 14 file extensions (Table 21). Tools B and C performed the best, followed by Tool E. However, none of the tools could classify the header information of all files, and Tools B and C did not support the same extensions. Moreover, only one tool supported the csv and hwpx extensions. The experiment involved altering the primary document extensions used in South Korea. The results of the file-signature analysis revealed some false positives, wherein files with the same signature were classified as the same document type. Classifying files based solely on file header signatures led to a higher false-positive rate; therefore, future improvements should include comparing byte sequences and format structures unique to each file to accurately determine its original extension. Because file extensions are simply names indicating the information they contain, proper signature interpretation was necessary for accurate file recognition.

4.2.4. DRM File Identification

The DRM file identification performance of the tools was tested across ten items, as listed in Table 22. Evidently, Tool E performed the best; however, the tool identified only five items, whereas the others could not identify one item. Before encrypted files are detected, identifying the DRM files is crucial using domestically implemented document security systems. Functionality improvements were required across all tools to enable custom signature analysis. DRM files help prevent the leakage of confidential data and intellectual property, and the evaluation results reflected the signature analysis employed for their identification and classification.

4.2.5. Encrypted File Identification

The encrypted file identification performance of the tools was tested across eight file extensions, as listed in Table 23. Tool E performed best, followed by Tool B. The experiment included five document types and three compressed files encrypted using standard encryption. The identification performance of the models varied depending on the encryption algorithm employed. Not all the encrypted files used in the experiment were identified. Tool E successfully identified all the encrypted document-type files. Additionally, only Tools B and E identified encrypted files that were likely to contain sensitive information.

4.2.6. File Preview

The evaluation of the tools’ file preview capability examined whether they support selective acquisition across 31 file types, including document, compound, and image files, as listed in Table 24. The results show that Tool C performed the best, followed by Tool B. Tool C supports preview for most file types, except for HWP and DB files. Tool B also supports most text-based files, except for CELL and HWPX. Other tools showed limited support for preview functionality. The file preview capability varies depending on internal and external modules, and in some cases, results differ depending on the local PC environment or limitations in virtualized environments such as VMware. This functionality enables investigators to identify legally protected or sensitive information and exclude unnecessary or inappropriate data from seizure. By filtering out irrelevant materials and focusing on evidence directly related to the case, file preview improves the efficiency of the investigation.

4.3. Seizure Phase

4.3.1. File and Folder Name Search

The collection and analysis performance of the tools were tested across seven evaluation items, as listed in Table 25. Tool E performed best, followed by Tool C. Based on the experimental results, logical image features exhibited different characteristics and formats for each tool. A key requirement for selective seizure is the ability to acquire logical images in a usable format and generate reports for the selected files; however, only Tool E offered this functionality. Tool D supported the VHD format, which enhanced its utility but entailed a long acquisition time. The supported physical image format was E01, and there were no tool-supported memory-dump reports. Logical images focus on files and folders accessible to the user, allowing for the selective seizure of specific data. Additionally, they maintain the file system structure when copying data, thereby increasing their accessibility for analysis. Furthermore, to effectively handle exceptional cases, forensic tools must support memory dumps, physical image acquisition, and report generation.

4.3.2. Extraction Evaluation

The extraction functionality of the tools was tested across the five items listed in Table 26. Tool E performed the best, followed by Tool B. All the tools supported report generation, with HTML being the most commonly supported format. In addition, all except one tool supported hash generation and hash sets. To complete the electronic evidence verification form, selective seizure tools must support these functions.

4.4. SSI Evaluation

It provides a comprehensive narrative explanation of how the Selective Seizure Capability Index was calculated in this study and why the SSI is a critical indicator for evaluating digital forensic tools in selective seizure scenarios. First, the SSI was designed to transform qualitative evaluation results into a reproducible and quantitative metric. In the experimental tables, each forensic tool was assessed using symbolic indicators O, □, △, and —, which represent different levels of functional support. To enable mathematical aggregation, these symbols were converted into numerical scores: O corresponds to 3 points, □ to 2 points, △ to 1 point, and—to 0 points. This conversion establishes a consistent numerical basis while preserving the original qualitative meaning of the evaluation. Next, the evaluation was conducted separately for each investigative phase: search, select, and seizure. Within each phase, multiple evaluation items were defined. For a given tool, the scores assigned to all items within a phase were summed to obtain the raw phase score. However, because the number of evaluation items differs across phases, a direct comparison of raw scores would be inappropriate. Therefore, each phase score was normalized by dividing it by the maximum possible score for that phase, calculated as three times the number of evaluation items. This normalization process ensures that all phase scores fall within a 0–1 range and are directly comparable. After normalization, the phase scores were aggregated into a single SSI value using a weighted summation. In this study, weights of 0.3 were assigned to both the search and select phases, while a higher weight of 0.4 was assigned to the seizure phase. This weighting scheme reflects the procedural importance of evidence acquisition, integrity verification, and reporting in determining evidentiary admissibility. The resulting SSI value, therefore, represents the overall degree to which a forensic tool supports selective seizure procedures across all investigative phases. Finally, for ease of interpretation, the SSI values were expressed as percentages by multiplying the normalized SSI by 100. For example, an SSI value of 0.71 indicates that the tool satisfies approximately 71% of the ideal selective seizure requirements defined by the evaluation model. The SSI is important for several reasons. First, it consolidates a large number of heterogeneous evaluation items into a single, interpretable indicator, enabling direct comparison between forensic tools. Second, it aligns tool evaluation with the procedural workflow of selective seizure, ensuring that performance is assessed in a manner consistent with real-world investigative practice. Third, the weighted structure of the SSI allows the evaluation to be adapted to different investigative priorities, such as emphasizing rapid on-site analysis or strict evidentiary admissibility. Finally, by providing a transparent and reproducible calculation process, the SSI enhances the objectivity and credibility of tool evaluation results, supporting both academic analysis and practical decision-making in digital forensic investigations. The Selective Seizure Capability Index provides substantial academic value in the performance evaluation of Windows forensic tools by advancing tool assessment from descriptive comparison to a structured, procedure-oriented evaluation methodology. Conventional studies on forensic tools often focus on the presence or absence of specific functions or on case-based effectiveness, which limits reproducibility and generalizability. In contrast, the SSI introduces a formalized mechanism for aggregating heterogeneous evaluation results into a coherent quantitative index, thereby strengthening methodological rigor. A primary contribution of the SSI lies in its ability to ensure fairness and comparability across evaluation dimensions. By converting qualitative assessment symbols into numerical scores and normalizing phase-level performance by the maximum attainable values, the SSI mitigates bias arising from unequal numbers of evaluation items across investigative phases. This normalization enables a balanced comparison of tools even when functional coverage differs substantially, which is a common challenge in forensic tool evaluation. Moreover, the SSI explicitly aligns performance assessment with the procedural workflow of selective seizure, structured around the search, select, and seizure phases. This phase-based aggregation reflects actual field investigation practices and distinguishes between analytical convenience and evidentiary completeness. As a result, tools are evaluated not merely on isolated technical features but on their capacity to support selective seizure as an integrated investigative procedure. The weighted aggregation employed in the SSI further enhances its academic relevance by allowing the evaluation model to reflect procedural priorities and legal considerations. Assigning a higher weight to the seizure phase emphasizes functions directly related to evidentiary integrity, verification, and reporting, which are critical for legal admissibility. At the same time, the weighting scheme remains adaptable, enabling researchers and practitioners to adjust phase importance according to investigative context or jurisdictional requirements without altering the underlying evaluation structure. From a normative perspective, the SSI also enables the quantification of principles that are traditionally addressed only at a conceptual level, such as proportionality and minimal intrusion. Performance in the selection phase directly influences the extent to which unnecessary data collection can be avoided. By incorporating these aspects into a measurable index, the SSI bridges the gap between the legal and ethical objectives of selective seizure and the technical capabilities of forensic tools. Importantly, the SSI should not be interpreted solely as a ranking metric. Rather, it functions as an analytical framework that supports both comparative assessment and diagnostic interpretation. The decomposition of the SSI into phase-specific components allows researchers to identify strengths and limitations of tools at each procedural stage, facilitating targeted improvements and meaningful cross-study comparison. Consequently, the SSI establishes a reproducible and extensible foundation for future research on forensic tool verification and selective seizure evaluation in Windows-based environments.

4.5. Discussion

This study proposed and applied a framework for evaluating the selective seizure capabilities of Windows forensic tools from an on-scene response perspective. The selective seizure workflow was structured into three stages—search, selection, and seizure—and six tools were comparatively validated under identical conditions using a dedicated dataset in a Windows 10 (22H2)/NTFS environment, confirming performance differences among the tools. In addition, by integrating the evaluation items, this study proposed the Selective Seizure Capability Index (Selective Seizure Capability Index), thereby quantitatively presenting tool suitability according to investigative context. Although the results were validated on Windows 10, given the continuity of NTFS structures and the core principles of processing major Windows artifacts, the findings can also be used as practical reference criteria for tool comparison and selection in Windows 11 environments. However, because this study is based on a VMware-controlled environment and a constructed dataset, it cannot fully reflect variables that arise in real field conditions, such as TPM/BitLocker, real-time I/O constraints, storage media condition, driver/firmware differences, and data fragmentation, corruption, or concealment. In addition, there are limitations in directly generalizing the results to heterogeneous environments such as macOS/Linux or APFS/exFAT/EXT; therefore, the conclusions are limited to the scope of verifying functional accuracy and reproducibility under controlled conditions.
Moreover, certain hardware-dependent conditions—such as TPM-based disk encryption, low-level I/O behaviors, or firmware-level artifacts—may not be fully reproduced in a virtualized environment. Future studies should therefore adopt a dual-validation approach that combines controlled virtual environments with physical hardware-based experiments to enhance external validity. Second, the scope of analysis focused primarily on file system artifacts and Windows event logs during the search and selection phases of selective seizure. Other increasingly important investigative domains, such as cloud storage services, instant messaging platforms, remote access tools, and containerized or virtualized execution environments, were intentionally excluded to maintain experimental clarity. As digital evidence environments continue to diversify, extending the proposed framework to cover these domains will be essential for maintaining its relevance in contemporary investigations. Third, the evaluation was conducted on a limited set of six portable, GUI-based forensic tools selected for their practical applicability in field investigations. To mitigate product bias, tool names and version identifiers were anonymized, and all tools were tested using their latest available versions at the time of evaluation. While this approach strengthened neutrality, it also constrained strict reproducibility by third parties. Future research may address this issue by documenting reproducible version indicators, such as build numbers, module versions, or hash values, without disclosing product identities, thereby balancing objectivity and replicability.
Finally, the present study did not explicitly incorporate usability and operational burden into the evaluation metrics. In real-world selective seizure scenarios, factors such as the number of procedural steps, required analyst expertise, degree of automation, and the interpretability of outputs can significantly affect investigative efficiency and error risk. Incorporating usability-oriented indicators alongside functional capabilities would further enhance the framework’s applicability to frontline investigative practice. Despite these limitations, this study contributes a structured and transparent evaluation framework that connects selective seizure functions with investigative efficiency and procedural compliance. By addressing the identified limitations, future research can extend the framework across platforms, environments, and investigative contexts, ultimately supporting more precise, proportionate, and legally robust digital evidence collection.

5. Conclusions

This study examined the importance of selective seizures based on digital evidence and evaluated the functionality of six widely used tools to identify areas of improvement. First, the characteristics of digital evidence were used to evaluate the requirements for securing it, specifically regarding identity, reliability, and relevance to meet the admissibility criteria; then, the procedures, laws, and case precedents governing the selective seizure of evidence related to criminal activities in the field were reviewed. Subsequently, an evaluation model for selective seizure tools was developed, encompassing key analysis items and a comprehensive dataset. Chapter 3 investigated new evaluation model analysis items for field response, reflecting the requirements covered in prior research on digital forensic tools. New field response verification requirements were created based on existing requirement design indicators, six types of digital forensic tools required for the design and evaluation of verification requirement models were selected, and datasets were developed. The results of the experiment, which involved three phases—search, select, and seize—revealed significant differences in the performance of the tools, allowing us to offer recommendations for improving their functionality. Specifically, in the search phase, Tools C and B outperformed the others in NTFS parsing, while Tools C and B demonstrated superior capabilities in Windows log analysis. In the selection phase, Tool C was most effective for file and folder name searches, Tool E for keyword searches, Tools B and C for file headers, Tool E for DRM and encrypted files, and Tool C for file previews. Tool E satisfied the evaluation criteria for data collection and extraction during the seizure phase. These findings offer valuable insights into the analysis and collection techniques of Windows forensic tools for field-based selective seizures. Therefore, they can assist forensic investigators in effectively analyzing and collecting digital evidence, thereby improving the efficiency and accuracy of their investigations. However, this study focused only on six portable tools implemented in an experimental environment comprising a virtual machine, an active system, Windows 10, and NTFS. Future research should evaluate a wider range of tools geared toward other operating systems [34,35], such as Windows 11 and MacOS. Additionally, future research should explore the integration of artificial intelligence and machine learning techniques in selective seizure tools, particularly for cloud-based environments. AI-powered analytics could enhance the accuracy and efficiency of evidence identification in cloud storage while also helping to address the challenges of data sovereignty and cross-jurisdictional investigations. The development of AI-assisted cloud forensic capabilities could provide investigators with more sophisticated tools for analyzing distributed digital evidence, though careful consideration must be given to maintaining the forensic integrity and admissibility of AI-processed evidence.
In addition, future investigations should consider incorporating various file systems and functions related to cloud storage [36,37], messaging applications, virtual environments, remote access programs, and third-party tools, all of which are being increasingly adopted. However, we expect that the findings of this study will contribute to the efficient acquisition of digital evidence using selective seizure tools, ultimately enhancing the capabilities of digital forensic investigations.

Author Contributions

Study conception and design: S.-H.K.; data collection: C.Y.; analysis and interpretation of results: C.Y. and S.-H.K.; draft manuscript preparation: S.-H.K. and C.Y. All authors have read and agreed to the published version of the manuscript.

Funding

This work was supported by the Institute for Information and Communications Technology Planning and Evaluation (IITP) grant funded by the Ministry of Science and ICT (MSIT, Korea, No. RS-2024-00456709, A Development of Self-Evolving Deepfake Detection Technology to Prevent the Socially Malicious Use of Generative AI).

Data Availability Statement

The original contributions presented in this study are included in the article. Further inquiries can be directed to the corresponding author.

Institutional Review Board Statementt

Not applicable.

Informed Consent Statement

Not applicable.

Conflicts of Interest

Sun-Ho Kim is employed by AbleSECU company. The company played no role in the design of the study, the collection, analysis, or interpretation of data, the writing of the manuscript, or the decision to publish the article.

References

  1. G. O. Presidential Decree, Republic of Korea. Regulations on Mutual Cooperation Between Prosecutors and Judicial Police Officers and General Investigative Principles, Article 41, Paragraphs 1, 2, 3. 1 November 2023. Available online: https://www.law.go.kr/lsInfoP.do?ancYnChk=0&lsId=013871 (accessed on 26 February 2026).
  2. Desktop Windows Version Market Share Republic of Korea. StatCounter Global Stats. Available online: https://gs.statcounter.com/windows-version-market-share/desktop/south-korea (accessed on 26 February 2026).
  3. Computer Forensics Tools & Techniques Catalog-Tool Search. Available online: https://toolcatalog.nist.gov/search/ (accessed on 26 February 2026).
  4. Desktop Hypervisor Solutions|VMware. Available online: https://www.vmware.com/products/desktop-hypervisor/workstation-and-fusion (accessed on 26 February 2026).
  5. Lee, S.Y. A Proposal to Establish an Independent Analysis Institution in Digital Evidence Seizure and Search. Comp. Crim. Law Rev. (Bijogyo Hyeongsa Beom Yeongu) 2025, 27, 193–239. [Google Scholar] [CrossRef]
  6. Lee, H. A Study on the Transfer of Irrelevant Information and the Seizure of Unrelated Information. Master’s Thesis, Seoul Nat’l University, Seoul, Republic of Korea, 2025. [Google Scholar]
  7. Lee, S.Y. A Study on Digital Evidence Screening Based on Metadata Similarity. Master’s Thesis, Sungkyunkwan University, Seoul, Republic of Korea, 2024. [Google Scholar]
  8. Cheon, S. A Study on Improvement Measures for Efficient On-Site Selective Seizure and Search of Digital Information: Focusing on the Analysis of Keyword Search Time and the Possibility of Metadata Modification. Ph.D. Thesis, Sungkyunkwan University, Seoul, Republic of Korea, 2024. [Google Scholar]
  9. Oh, J. A Study on Problems and Improvement Measures Following the Conceptual Shift in Selective Seizure of Digital Evidence. Master’s Thesis, Seoul Nat’l University, Seoul, Republic of Korea, 2023. [Google Scholar]
  10. Heo, J. A Study on Problems in Selective Seizure of Digital Evidence and Efficient Seizure Measures. Master’s Thesis, Seoul Nat’l University, Seoul, Republic of Korea, 2023. [Google Scholar]
  11. Kim, Y. A Study on Issues with the ‘On-Site’ and ‘Selective’ Principles in Search and Seizure of Digital (Electronic) Evidence and Technical/Legal Improvement Measures: Focusing on the Need to Amend Article 106(3) of the Criminal Procedure Act. Master’s Thesis, Seoul Nat’l University, Seoul, Republic of Korea, 2022. [Google Scholar]
  12. Yoon, S.; Lee, S. A study on digital evidence automatic screening system. J. Digit. Forensics KDFS 2020, 14, 239–251. [Google Scholar]
  13. Cho, G. A digital forensic analysis for directory in Windows file system. J. Korea Soc. Digit. Ind. Inf. Manag. 2015, 11, 73–90. [Google Scholar] [CrossRef] [Scilit]
  14. Shin, Y. A Study on Field Detection Techniques for Non-Searchable Email Attachments. Master’s Thesis, Seoul National University, Seoul, Republic of Korea, 2019. [Google Scholar]
  15. Lee, T.-R.; Shin, S.-U. Reliability verification of evidence analysis tools for digital forensics. J. Korea Inst. Inf. Secur. Cryptol. 2011, 21, 165–176. [Google Scholar]
  16. Ham, J.; Joshua, I.J. A study on the comparison of modern digital forensic imaging software tools. J. Korean Inst. Internet Broadcast. Commun. 2019, 19, 15–20. [Google Scholar]
  17. Park, S.; Hur, G.; Lee, S. Development of a set of data for verifying partition recovery tool and evaluation of recovery tool. J. Korea Inst. Inf. Secur. Cryptol. 2017, 27, 1397–1404. [Google Scholar]
  18. Quick, D.; Choo, K.-K.R. Big forensic data reduction: Digital forensic images and electronic evidence. Clust. Comput. 2016, 19, 723–740. [Google Scholar] [CrossRef] [Scilit]
  19. Kim, M.-S.; Lee, S. Development of Windows forensic tool for verifying a set of data. J. Korea Inst. Inf. Secur. Cryptol. 2015, 25, 1421–1433. [Google Scholar] [CrossRef] [Scilit]
  20. Lee, D. A Quality Evaluation Model Based on ISO/IEC 9126 for Digital Forensic Tools. Master’s Thesis, Soongsil University, Seoul, Republic of Korea, 2015. [Google Scholar]
  21. Park, J.; Lyle, J.R.; Guttman, B. Introduction to the NIST digital forensic tool verification system. Rev. KIISC 2016, 26, 54–61. [Google Scholar]
  22. CFReDS Portal. Available online: https://cfreds.nist.gov/ (accessed on 26 February 2026).
  23. Hosting Various Seminars Related to Digital Forensics from 2001 to the Present, DFRWS. Available online: https://dfrws.org/ (accessed on 26 February 2026).
  24. National Institute of Standards and Technology (NIST). Computer Forensics Tool Testing (CFTT) Program. Available online: https://www.nist.gov/itl/ssd/software-quality-group/computer-forensics-tool-testing-program-cftt (accessed on 4 March 2026).
  25. National Institute of Standards and Technology (NIST). Computer Forensic Reference Data Sets (CFReDS). Available online: https://www.nist.gov/programs-projects/computer-forensic-reference-data-sets (accessed on 4 March 2026).
  26. Private Qualification Information Service (PQI). Digital Forensics Expert Qualification Exam: Issuing Body—Korea Forensic Society; Co-Issuing Body—Korea Internet & Security Agency (KISA). Available online: https://www.pqi.or.kr/inf/qul/infQulBasDetail.do?qulId=2672 (accessed on 4 March 2026).
  27. Korea Forensic Society. Digital Forensics Expert Qualification Exam Portal. Available online: https://exam.forensickorea.org/web/main.do (accessed on 4 March 2026).
  28. Hitchcock, B.; Le-Khac, N.-A.; Scanlon, M. Tiered forensic methodology model for Digital Field Triage by non-digital evidence specialists. Digit. Investig. 2016, 16, S75–S85. [Google Scholar] [CrossRef] [Scilit]
  29. Rogers, M.K.; Goldman, J.; Mislan, R.; Wedge, T.; Debrota, S. Computer Forensics Field Triage Process Model. J. Digit. Forensics Secur. Law 2006, 1. [Google Scholar] [CrossRef] [Scilit]
  30. Horsman, G.; Lyle, J.R. Dataset construction challenges for digital forensics. Forensic Sci. Int. Digit. Investig. 2021, 38, 301264. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  31. Stoykova, R.; Franke, K. Reliability validation enabling framework (RVEF) for digital forensics in criminal investigations. Forensic Sci. Int. Digit. Investig. 2023, 45, 301554. [Google Scholar] [CrossRef] [Scilit]
  32. ISO/IEC 27037:2012; Information Technology—Security Techniques—Guidelines for Identification, Collection, Acquisition and Preservation of Digital Evidence. ISO/IEC: Geneva, Switzerland, 2012. Available online: https://www.iso.org/standard/44381.html (accessed on 4 March 2026).
  33. ISO/IEC 27042:2015; Information Technology—Security Techniques—Guidelines for the Analysis and Interpretation of Digital Evidence. ISO/IEC: Geneva, Switzerland, 2015. Available online: https://www.iso.org/standard/44406.html (accessed on 4 March 2026).
  34. Domingues, P.; Frade, M.; Negrão, M. Digital Forensic Artifacts of FIDO2 Passkeys in Windows 11. In Proceedings of the 19th International Conference on Availability, Reliability and Security (ARES’24), Vienna, Austria, 30 July–2 August 2024; pp. 1–10. [Google Scholar]
  35. Plum, J.; Dewald, A. Forensic APFS File Recovery. In Proceedings of the 13th International Conference on Availability, Reliability and Security (ARES’18), Hamburg, Germany, 27 August 2018; pp. 1–10. [Google Scholar]
  36. Herman, M.; Iorga, M.; Salim, A.M.; Jackson, R.H.; Hurst, M.R.; Leo, R.; Lee, R.; Landreville, N.M.; Mishra, A.K.; Wang, Y.; et al. NIST Cloud Computing Forensic Science Challenges; NIST Interagency/Internal Report (NIST IR) 8006; NIST: Gaithersburg, MD, USA, 2020; pp. 1–87.
  37. Chung, H.; Park, J.; Lee, S.; Kang, C. Digital forensic investigation of cloud storage services. Digit. Investig. 2012, 9, 81–95. [Google Scholar] [CrossRef] [Scilit]
Figure 1. Design process of the selective seizure tool evaluation model.
Figure 1. Design process of the selective seizure tool evaluation model.
Digital 06 00029 g001
Figure 2. Experimental procedure for evaluating the selective seizure functions of the six tools.
Figure 2. Experimental procedure for evaluating the selective seizure functions of the six tools.
Digital 06 00029 g002
Table 1. Digital forensic tool datasets used in previous projects and studies.
Table 1. Digital forensic tool datasets used in previous projects and studies.
No.CategoryProject/ResearchFormat
1InstitutionComputer Forensic Reference Dataset
(CFReDS) Project
E01, DD
2Computer Forensic Tool Testing ProjectE01, DD
3Digital Forensic Tool Testing (DFTT)DD
4Naval Postgraduate School Digital Forensics Corpus (NPS Corpora)File Dump, E01,
DD, packet dump File
5ForensicKBE01, DD, File
6Prior
Research
ISO/IEC 9126-based Quality Evaluation Model for
Digital Forensic Tools
Live
7Reliability Evaluation through Verification of the Analytical Functions of Computer Forensic ToolsDD
8Development of a Verification Dataset for Windows Forensic ToolsVMDK
9Configuration of a Computer Forensic Tool Verification Image
Suitable for Domestic Environments
10Reliability Verification of Evidence Analysis Tools for Digital ForensicsE01, DD, File
Table 2. File system validation requirements.
Table 2. File system validation requirements.
NumbersVerification Requirements
1Recognizes the specified file system and analyzes the metadata.
2Recognizes and analyzes all files registered in the file system.
3Analyze accurate time information for all files and folders.
4Recognizes and processes fragmented files.
5Recognizes and analyzes all files and folders registered in the GUID partition.
6Handles and recognizes incorrect partition information.
7Shows the location on the digital source for all files.
8Detects hidden partitions and recognizes all files and folders.
9Analytical tools provide data extraction and analysis functions for evidence media to identify evidence.
10Analysis tool functions always output the same results when the same input data is given in the same environment.
11Analysis tool functions keep input data revisions to a minimum and report modifications when they occur.
12The analysis tool supports at least one file system and accurately recognizes the file systems and metadata supported by the tool.
13The analysis tool records a log of events performed.
14Analysis tool functions report errors that occurred during execution.
Table 3. File search validation on requirements.
Table 3. File search validation on requirements.
NumbersVerification Requirements
1The results of considering the query are the same as the three matching the query.
2Navigation is possible with one or more character encodings.
3You can explore strings in Slack space.
4If you specify a specific area within the evidence disk as the search range, results are output only at that point.
5You can use regular expressions to navigate.
6You can search with Hash Set (Hash Set).
7You can explore the full spectrum of digital sources. (including slack, parity, deleted areas, and between files)
8You can extract any file from a supported file system.
9If a reorganization-related error occurs while extracting a file, an error report is possible.
10The collected files are collected to the original.
11When extracting a file, unreadable parts are potentially as extractable data.
12Users are considering when storage space is low.
13Korean language support is available.
14Invented the file system information contained in the validation data.
15Preserves hash values (minimum MD5, SHA 1) for all files included in validation data.
16Combating the fragmentation status and count of some of the files included in the validation data.
17Validates keyword searches in the NTFS file system.
18Validates the ability to extract data from NTFS deleted files.
19Verify the NTFS automatic detection feature.
20Verify the data extraction function in the basic data carving function.
21If a subset of the string search function is specified, results are output only from that subset.
22A limit on the number of matches is applied when searching for sorted/unsorted subsets in a string search.
23The screen is displayed according to the specified text direction.
24Synonym search is supported.
25When performing a fuzzy search, it must match a close misspelling (close misspelling) in the query string.
26When performing a phonetic search (phonetic search), it must match words pronounced the same as the query string.
27If you provide a predefined query, the response returned must be the same set of matches for the query.
28It must support logical operations such as And, or, and not.
29Analytical tools should provide data extraction and analysis capabilities to identify evidence.
30You must be able to browse regardless of capitalization.
Table 4. Application analysis verification requirements.
Table 4. Application analysis verification requirements.
NumbersVerification Content
1Log file analysis must be able to recognize at least one or more log file formats and provide a function to search and filter desired events.
2It is necessary to be able to analyze time information on internal data according to the environment in which the original was created.
3System/user settings information analysis must be able to analyze information about the operating system, information about users, and information about installed applications.
4Log file analysis must be able to accurately recognize and report on various log file formats through documentation provided by the tool (including usage, purpose, operating mechanism, and system requirements).
Table 5. Data deletion, concealment verification requirements.
Table 5. Data deletion, concealment verification requirements.
NumbersVerification Content
1The deleted file recovery function must support the recovery function in a file system confirmed by documents provided by the tool (a set of materials describing usage, purpose, operation, system requirements, etc.).
2The deleted file recovery function must identify all deleted file system objects that can be recovered from metadata maintained after the file system object has been deleted.
3The deleted file recovery function must report errors that occurred in constructing recovered objects.
4The deleted file recovery function must configure a recovered object for each deleted file system object from the remaining metadata.
5Each recovered object must include all unallocated data blocks identified in the remaining metadata.
6Each recovered object must consist only of data blocks from the deleted block pool.
7If the deleted file recovery function generates estimated content, the recovered object must be composed of data blocks from the original file system object identified in the remaining metadata.
8If the deleted file recovery function generates estimated content, any data blocks in the recovered object must be organized in the same logical order as the original file system object identified in the remaining metadata.
9If the deleted file recovery function generates estimated content, the recovered object must consist of the same number of blocks as the original file system object.
10Verify the FAT deleted file extraction function.
11Verify the NTFS deleted file extraction function.
12Verify the basic data carving function.
Table 6. Verification/report requirements.
Table 6. Verification/report requirements.
NumbersVerification Content
1The analysis tool must output the results of the analysis performed in the form of a report.
2The hash values of all files belonging to the verification data are preserved. At this time, the hash function uses at least MD5 and SHA1.
3Analysis tool functions must always output the same results when given the same input data in the same environment.
4Timeline analysis must be able to extract information such as creation, modification, access time, and ownership of a file through MAC (modified, modified, change of status) time analysis and must be able to sort and list in chronological order using this information.
5Analysis tool functions must report errors that occurred during execution.
Table 7. Phases and items employed for evaluating the analysis functions of selective seizure tools.
Table 7. Phases and items employed for evaluating the analysis functions of selective seizure tools.
No.PhaseEvaluation Item
1Search
  • NTFS Parsing
    (BitLocker analysis, Partition MFT, VBR (MBR, GPT) deletion, damage analysis, $MFT, $MFT Entry,
    $Standard_Information, $FileName, $MFT deletion information)
  • File and folder access log analysis
    (JumpList, Link File, Shellbag MRU, Windows.edb, ActivitiesCache.db, etc.)
  • Application execution log analysis
    (Prefetch, ActivitiesCache.db, AmCache, SRUMDB)
  • Data-transmission log analysis
    (Setupapi.log, Registry, EventLog, AmCache)
  • Information search log analysis
    (Chrome, Edge, Whale: History, Download, Password, Cache, Cookies)
  • Suspicious activity log analysis
    (EventLog: System ON/OFF, User Account Changes, System Time Changes)
2Select
  • Information search
    (File and folder name search, file keyword analysis, file header classification, DRM files, encrypted files, etc.)
3Seizure
  • Collection and Extraction
    (Logical image, physical image, memory acquisition, report generation, hash verification, error handling report)
Table 8. Portable tools evaluated in this study.
Table 8. Portable tools evaluated in this study.
No.CategoryTool NameBased on the Latest Versions (23.11)Release and
First Version
1CommercialMagnet Outrider4.02019
2Non-commercialAutopsy4.19.32010
3CommercialX-Ways20.91995
4CommercialOS Forensic Professional and Bootable Edition10.0.10162011
5CommercialDFAS Pro1.2.2.142011
6CommercialBelkasoft Triage1.3.137232021
Table 9. Symbols for presenting the evaluation results of selective seizure tool functions.
Table 9. Symbols for presenting the evaluation results of selective seizure tool functions.
SymbolDescription
OMeets all details of the verification items
Meets three or more details of the verification items
Meets three or more details of the verification items but requires manual analysis
-Does not meet any detail of the verification items
Table 10. Laptop specifications and the VMware virtual machine environment used for the experiments.
Table 10. Laptop specifications and the VMware virtual machine environment used for the experiments.
No.TypeSpecifications
1LaptopCPUIntel Core i5-1035G4 CPU @ 1.10 GHz 1.50 GHz
RAM/HDD8 GB/Mtros SSD NVMe M.2
2Virtual MachineWindowsWindows 10 PRO 64-bit 22H2 NTFS configuration
VersionVMware Workstation PRO 17.5
CPU/RAM4 Core/4 GB
Table 11. Details of the evaluation items.
Table 11. Details of the evaluation items.
PhaseParameterDescription
SearchPortableVerify the execution and automated analysis functionality of the portable GUI-based tool selection.
BitLocker identification and support for decryption after entering the passwordVerify support for recognizing BitLocker-encrypted partitions on Windows and unlocking and decrypting them after entering the recovery key or password.
Partition damageVerify support for recovering deleted or damaged partitions, master boot record (MBR), GUID partition table (GPT) (MFT, volume boot record (VBR)).
$MFT analysisVerify support for recognizing NTFS and parsing $MFT.
($MFT structure parsing, size information).
$MFT attribute timestamp analysis ($SI, $FN)Verify recognition of $MFT and support for file-information and metadata analysis.
($SI creation, modification, access, MFT modification, attribute flag information, $FI parent directory file reference address, creation, modification, access, MFT modification, file allocated size, actual file size, attribute flag, name length, name type, name information support).
$MFT deletionVerify deleted record information in $MFT entries.
(Unallocated file, file name, creation, modification, access).
JumpListVerify document file-access records.
(Analysis count, file name, link creation, link modification, link access, target creation, target modification, target access, volume name, volume S/N, size, path, original path).
Link fileVerify document file-access records.
(Analysis count, file name, link creation, link modification, link access, target creation, target modification, target access, volume name, volume S/N, size, path, original path).
Shellbag MRUVerify folder access records.
(Analysis count, folder name, visit time, creation time, access time, modification time, path, original path).
ActivitesCache.dbVerify document file-access records.
(Analysis count, display text, last modification time, app ID, path, original path).
Windows.edbVerify document file records.
(Document count, file name, creation, modification, file type, file path, content, original path).
Volume shadowVerify backup records of three documents.
(Analysis count, file name, creation time, original path).
$LogfileVerify document file records.
(Analysis count, events, original path).
$UsnJrulVerify document file records.
(Analysis count, events, original path).
Thumbnail.dbVerify thumbnail cache image file records.
(Image name, original path).
$Recycle.binVerify records of deleted files.
(File count, $R, $I).
PrefetchVerify records of executed programs.
(Analysis count, program name, execution time, execution count, path, original path).
Program executionVerify records of executed programs.
(Analysis count, program name, execution time, execution count, user, path, original path).
AmCacheVerify record of the executed program.
(Key time, key name, name, publisher, size, original path).
SRUMDBVerify resource-usage records of executed programs.
(Creation time, program, original source).
External storage deviceRegistryVerify external storage device records.
(Model name, first connection time, last connection time, disconnection time, serial number, volume name, original path).
Setupapi.logVerify external storage device records.
(Model name, first connection time, original path).
EventLogVerify external storage device records.
(Event ID, connection/disconnection time, device information, original path).
Network
connection
WirelessVerify wireless network records.
(Network name, last connection time, original path).
WiredVerify wired-network records.
(Adapter name, IP, subnet mask, DHCP, original path).
Web browser
(Chrome, Edge, Whale)
Web AccessVerify internet-access records.
(Analysis count, accessed website, access time, original path).
Search TermsVerify web search term records.
(Analysis count, search terms, access time, original path).
DownloadsVerify records of files downloaded from the internet.
(Analysis count, website, downloaded file, download time, original path).
PasswordsVerify saved web ID/password records.
(Save count, creation time, website, original path).
CacheVerify web-cache file records.
(Analysis count, cache file, access time, website, original path).
CookiesVerify internet cookie records.
(Analysis count, cookie file, access time, website, original path).
EventLogSystem
ON/OFF
Verify system ON/OFF records.
(ON time, OFF time, computer name, EventID, original path).
User Account ChangesVerify system user account change information.
(Account name, event time, EventID, original path).
System
Time Changes
Verify system time change information.
(Previous time, new time, user ID, EventID, original path).
SelectFile name searchVerify search of Korean file names.
“Network Diagram.pptx, Risk Burden.pdf, Office Lease Contract.hwp”
Verify support for logical operators AND, OR.
Verify support for regular-expression searches.
“Forensic[, -]Science, Sungkyunkwan [0–9가-힣] University, http://www\.[가-힣]+\.com, C:\\Images\\KakaoTalk\\.gif, 02[-) ]*3290-1212”.
Keyword analysisVerify search for keywords “forensics, digital forensics, selection, tools, Sungkyunkwan University” in document file extensions.
(cell, csv, doc, docx, hwp, hwpx, pdf, pptx, rtf, show, txt, xls, xlsx).
File header identificationDocumentscell, csv, doc, docx, hwp, hwpx, pdf, pptx, rtf, show, txt, xls, xlsx.
Digital Rights Management (DRM)Verify the identification of Fasoo, SoftCamp, and Markany.
Encrypted FilesVerify the identification of doc, docx, hwp, ppt, pptx, 7z, tar, and zip.
PreviewDocumentscell, csv, doc, docx, hwp, hwpx, pdf, pptx, rtf, show, txt, xls, xlsx.
Compound FilesVerify the identification of pst, ost, sqlite, db, 7z, zip, tar, egg, and rar.
ImagesVerify the identification of awd, psd, dwg, bmp, png, psp, jpeg, and jpg.
SeizureLogical imageVerify support for logical image acquisition.
Physical imageVerify support for physical image acquisition.
Memory collectionVerify support for memory-dump collection.
ReportVerify the generation of a report for logical image acquisition (file name, path).
Hash verificationVerify the inclusion of hash information in the report and support for calculating at least two hashes.
Error handling logSupport for logging errors occurring in the tool and other logs.
Table 12. VMDK dataset.
Table 12. VMDK dataset.
Verification ItemFile NameFile SizeFile Hash Value (MD5, SHA1)
SearchMBR-000002.vmdk17 GBd666ad43460de6f9955e4e045b10ba8e 54608a7ea3437e3ea6952b5722cfe4baa52fa2da
Basic Sample Machine-cl1.vmdk22.9 GB62ac1cfdea9a1d3b13395c6eb9c9ecc8
e3e33f24909b56a5fc57491b17621310d8a76a66
Search, SelectWindows 10 ×64 (1). vmdk61.9 GBd666ad43460de6f9955e4e045b10ba8e
54608a7ea3437e3ea6952b5722cfe4baa52fa2da
SeizureBasic Sample Machine-cl1.vmdk25.3 GBb11f85b705402c86cce19ea3ee8dec0b
f2925883e67c719f01ae57762d82cd8699a1d206
Table 13. NTFS parsing results.
Table 13. NTFS parsing results.
No.Evaluation ItemTool
AB **C *DEF
1BitLocker Support---O--
2$MFT AnalysisOOOOOO
3$MFT Recognition-O-
4MBR (VBR) Damage---O--
5MBR (MFT)
Partition Deletion
-OO---
6GPT (VBR) Damage--O---
7GPT (MFT)
Partition Deletion
--O---
8MFT
File Deletion
-OO-O-
*: The most recommended tool. **: Second recommended tool. The same explanations applies to the following tables.
Table 14. File and folder access log analysis results.
Table 14. File and folder access log analysis results.
No.Evaluation ItemTool
ABCD **E *F
1JumpList---
2Link File□ *O
3Shellbag MRU-O-
4ActivitesCache.db--OO-
5Windows.edb----O-
6Volume Shadow-----
7$Logfile----O-
8$UsnJrul----O-
9Thumbnail.db---OO-
10$Recycle.bin-OO-O-
Table 15. Application execution log analysis results.
Table 15. Application execution log analysis results.
No.Evaluation ItemTool
ABCD **E *F
1PrefetchOOO
2Program Execution--OO-
3AmCache-OO-
4SRUMDB--O-
Table 16. Data-transmission log analysis results.
Table 16. Data-transmission log analysis results.
No.Evaluation ItemDetailsTool
ABC *DE **F
1Network
Connection
Wireless--OO-
2Wired---O-
3External Storage DeviceRegistry-OOO-
4Event Log--O--
5Setup.API--O-
6AmCache-OO-
Table 17. Internet search log analysis.
Table 17. Internet search log analysis.
No.BrowserEvaluation ItemTool
ABC **DE *F
1Google
Chrome
Web Access-OOO-
2Search Terms-OOO-
3Downloads-OOO-
4Passwords------
5Cache-O-O-
6Cookies-O-O-
7Microsoft
Edge
Web Access-O-OO-
8Search Terms-O-OO-
9Downloads-O-OO-
10Passwords---OO-
11Cache-O--O-
12Cookies-O--O-
13Naver
Whale
Web Access----O-
14Search Terms----O-
15Downloads----O-
16Passwords------
17Cache----O-
18Cookies----O-
Table 18. Suspicious activity analysis results (Eventlog).
Table 18. Suspicious activity analysis results (Eventlog).
No.Evaluation ItemTool
ABC *D **E **F
1System
ON/OFF
--OO-
2User Account
Changes
-----
3System Time
Changes
-----
Table 19. File and folder name search analysis results.
Table 19. File and folder name search analysis results.
No.Evaluation ItemTool
ABC *DE **F
1File Name-OOOO-
2Folder Name--O---
3Regular Expression-----
Table 20. Keyword Search Analysis Results.
Table 20. Keyword Search Analysis Results.
No.File TypeTool
ABC **DE *F
1cell-O-O-
2csv-OO-O-
3doc-
1 hit
-
2 hits
O-O-
4docx-
1 hit
-
2 hits
O-O-
5hwp-OO-O-
6hwpx----O-
7pdf-OO-O-
8ppt-
1 hit
OO-O-
9pptx O-O-
10rtf-
1 hit
-
2 hits
--O-
11show---O-
12txt-O-O-
13xls-OO-O-
14xlsx-OO-O-
Table 21. File header classification results.
Table 21. File header classification results.
No.File TypeTool
AB *C *DE **F
1cell----O-
2csv--O---
3doc-OO---
4docx-OO-O-
5hwp-OO-O-
6hwpx----O-
7pdf-OOOO-
8ppt-OO --
9pptx-OO --
10rtf-OO-0-
11show------
12txt-O-O--
13xls-OO-O-
14xlsx-OO---
Table 22. DRM file identification results.
Table 22. DRM file identification results.
No.SoftwareTool
ABCDE *F
1Fasoo------
2------
3------
4Softcamp----O-
5------
6------
7Markany----O-
8----O-
9----O-
10----O-
Table 23. Encrypted File Identification Results.
Table 23. Encrypted File Identification Results.
No.File TypeTool
AB **CDE *F
1doc-O--O-
2docx-OO-O-
3hwp----O-
4ppt----O-
5pptx-OO-O-
67z-O----
7tar------
8zip-O--O-
Table 24. File preview evaluation results.
Table 24. File preview evaluation results.
No.Evaluation ItemFile TypeTool
AB **C *DEF
1Document Filescell--O---
2csv-OO---
3doc-OO---
4docx-OO---
5hwp-OO---
6hwpx------
7pdf-OO---
8ppt-OO---
9pptx-OO---
10rtf-OO---
11show-OO---
12txt-OO---
13xls-OOO--
14xlsx-OO---
15Compound Filespst-OOOO-
16ost-OOOO-
17sqlite-O--O-
18db-O--O-
197z--OO--
20zip--OO--
21Tar--OO--
22egg--O---
23rar--OO--
24Image Files
(EXIF Support)
awd--O-O-
25psd-OO-O-
26dwg--O-O-
27bmp-OO
exif
O
exif
O-
28png-O
exif
O
exif
O
exif
O
exif
-
29psp--O
exif
O
exif
--
30jpeg--O
exif
O
exif
O
exif
-
31jpg-O
exif
O
exif
O
exif
O
exif
-
Table 25. Collection evaluation result.
Table 25. Collection evaluation result.
No.Evaluation ItemDetailsTool
ABC *DE **F
1Logical ImageImage Format--O
ctr
O
vhd
O
zip, dd
-
2Report---O
Save Error
O
csv, txt
-
3Time Taken for 200,000 Files --13 min180 min34 min-
4Memory DumpImage FormatO
bin
---O
raw
O
mem
5Report------
6Physical ImageImage Format--OOO-
7Report--O
txt
O
txt
O
txt
-
Table 26. Extraction evaluation results (field investigation confirmation form).
Table 26. Extraction evaluation results (field investigation confirmation form).
No.ItemTool
AB **CDE *F
1Report SupportOOOOOO
2Report Formattxt, htmlhtml,
excel,
text,
kml,
stix,
tsk file
htmltxttxt, csv,
excel
html
3Hash Support-OOOOO
4Hash Set-OOOOO
5Error Handling ReportOOO--O
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Share and Cite

MDPI and ACS Style

Kim, S.-H.; Yoon, C. Designing and Validating a Forensic Evaluation Model for Selective Seizure Capabilities in Windows Forensic Tools. Digital 2026, 6, 29. https://doi.org/10.3390/digital6020029

AMA Style

Kim S-H, Yoon C. Designing and Validating a Forensic Evaluation Model for Selective Seizure Capabilities in Windows Forensic Tools. Digital. 2026; 6(2):29. https://doi.org/10.3390/digital6020029

Chicago/Turabian Style

Kim, Sun-Ho, and Cheolhee Yoon. 2026. "Designing and Validating a Forensic Evaluation Model for Selective Seizure Capabilities in Windows Forensic Tools" Digital 6, no. 2: 29. https://doi.org/10.3390/digital6020029

APA Style

Kim, S.-H., & Yoon, C. (2026). Designing and Validating a Forensic Evaluation Model for Selective Seizure Capabilities in Windows Forensic Tools. Digital, 6(2), 29. https://doi.org/10.3390/digital6020029

Article Metrics

Back to TopTop