Guides for Investigators & Police
A practical, lawful reference series for cyber-crime investigators, organised by domain. Learn how to preserve digital evidence, request telecom and platform data, trace funds, route cross-border cases, and run open-source intelligence. Educational reference only, not legal advice.
New — Forensic Tools. Turn a platform records response into an investigation-ready report with the Facebook LERS Data Analyzer — see all our Forensic Tools.
Foundations
The cross-cutting essentials every cyber investigation rests on: preserving digital evidence and chain of custody, routing cross-border requests (MLAT, LERS, Interpol), emergency disclosure requests, and open-source intelligence.
Following the Money: How US Investigators Get Bank Records, SARs and FinCEN Data
Financial records win fraud cases. A guide for US investigators on the tools that move money evidence: grand jury subpoenas and the RFPA, Suspicious Activity Reports and the no-tipping-off rule, FinCEN's 314(a) and 314(b) programs, the Financial Fraud Kill Chain, and FinCEN's Rapid Response Program for funds wired abroad.
Read guideThe Stored Communications Act: How US Police Legally Compel Online Data
Subscriber data, transaction records, or message content: in the United States each tier needs a different legal instrument. A plain guide to the SCA's three-tier process (subpoena, 2703(d) order, search warrant), preservation letters, the Carpenter rule, the CLOUD Act, and non-disclosure orders.
Read guideWriting a Cyber-Forensic Report That Holds Up in Court
A practical guide for investigators on structuring a defensible cyber-forensic report: documenting methodology, hashes and tools, separating fact from opinion, the electronic-evidence certificate, and the report sections that survive cross-examination.
Read guideAn OSINT Toolkit for Cyber Police
A practical, lawful OSINT toolkit for cyber-police: a tool matrix, a defensible evidence workflow, and the legal, ethical and OPSEC boundaries that keep cases safe.
Read guideMLAT vs LERS vs Interpol: Which Channel, When
MLAT vs LERS vs INTERPOL: which cross-border channel gets you data, evidence, or a person, what each can compel, typical speed, and how to choose fast.
Read guideEmergency Disclosure Requests (EDRs), Explained: For Law Enforcement
Emergency Disclosure Requests (EDRs) explained for law enforcement: the 18 U.S.C. 2702 good-faith standard, how to submit one, platform channels and forgery risk.
Read guideDigital Evidence: Chain of Custody and Preservation Requests
How investigators keep digital evidence admissible: chain of custody, MD5/SHA-256 hashing, 2703(f) preservation, and India's BSA 2023 Section 63 certificate.
Read guideMobile
Phones, SIMs and telecom data: CDR, IPDR and tower dumps, SIM-swap investigation, device forensics and the records held by messaging and app providers.
Geofence and Keyword Warrants: What US Investigators Can and Can't Get in 2026
Reverse-location and reverse-keyword warrants are powerful and legally unsettled. A guide for US investigators: how the three-step geofence process works, the circuit split (Smith vs Chatrie), the Supreme Court case now pending, and why Google's move to on-device location has changed the game.
Read guideInside a Seized Smartphone: What Investigators Can and Cannot Extract
A practical guide to mobile device forensics on a seized handset: the four extraction levels, what each yields, why modern encryption and lock states often defeat extraction, how to preserve a phone, and admissibility.
Read guideCDR, IPDR and Tower Dumps: An Investigator's Guide to Telecom Data Requests
CDR, IPDR and tower dumps explained for investigators: what each telecom record proves, the lawful India process under BNSS, and how Carpenter compares.
Read guideCrypto
Following the money on-chain: tracing transactions, serving exchanges and VASPs, freezing stablecoins, and seeing through mixers and bridges.
Freezing and Seizing Crypto: From Exchange Request to Wallet Seizure
A field guide for investigators on the action that follows tracing: compelling exchanges to freeze and disclose accounts, seizing self-custodied wallets and seed phrases, and preserving custody, valuation and admissibility across borders.
Read guideHow to Trace a Cryptocurrency Transaction: A Guide for Investigators
How investigators lawfully trace a cryptocurrency transaction: blockchain tracing, the KYC exchange chokepoint, tools, mixers, the travel rule and legal process.
Read guideCloud
Data held by cloud and SaaS providers: making lawful requests, obtaining logs, and attributing a server or hosted service to a real operator.
Microsoft 365 and Google Workspace: An Investigator's Guide to SaaS Audit Logs
How investigators obtain and read Microsoft 365 and Google Workspace audit logs to prove account takeover and business email compromise, why logging must be enabled before an incident, and when to ask the org versus serve the provider.
Read guideCloud Evidence: Getting Data from AWS, Azure and Google Cloud
How to get evidence from the major cloud providers: the shared-responsibility boundary, identifying the account behind an IP, preservation, the AWS, Azure and Google law-enforcement portals, the US CLOUD Act and bilateral agreements, and the India, US, UK and EU framework compared.
Read guideAI
Investigating synthetic media and AI-enabled crime: deepfakes and voice clones, AI-generated evidence, and abuse of generative tools.
AI-Enabled Fraud: Investigating Voice Clones, Scam Chatbots and Synthetic Identities
A practical guide for police and cybercrime investigators working AI-enabled fraud: tracing voice-clone and deepfake CEO scams, AI chatbots, pig-butchering automation and synthetic-identity KYC fraud through the money, platform and telecom trail they leave.
Read guideInvestigating Deepfakes and Synthetic Media
A practical guide to investigating deepfakes and synthetic media: why detection is unreliable, building a provenance case with C2PA and SynthID, a verification and chain-of-custody workflow, the scale of the threat, and the India, US, UK and EU legal framework compared.
Read guide