HRD Forensic Guidebook

← Back to Guidebook

Part IV — Operational Standards and Legal Admissibility

Evidence collection standards, chain of custody, volatile data capture, cryptographic hashing, ethical guidelines, and legal barriers - for Kenyan Human Rights Defenders.

4.1 Standardising Evidence Collection and Chain of Custody

The fundamental goal of forensic evidence collection is to preserve the original state of digital artefacts in a manner that satisfies Section 106B of the Kenya Evidence Act - proving that evidence is authentic, unaltered, and was collected by a known, accountable person at a documented time. The standard phrase used in legal challenges is 'best evidence' - courts expect forensic evidence to represent the best possible preservation of the original.

LEGAL REQUIREMENT | Kenya Evidence Act Cap.80, s.106B | For electronic evidence to be admissible: the device must have been operating normally at time of collection; the record must not have been altered since collection (proven by cryptographic hash); and a certificate of authenticity signed by a responsible official must accompany the evidence in court.

4.1(a) Tiered Evidence Collection - Matching Capability to Responder Level

Not every HRD has access to professional forensic tools. The tiered model below ensures that every responder - regardless of technical level - can collect evidence in a legally useful way. The goal at every tier is the same: preserve the artefact in its original state, document who touched it and when, and generate a cryptographic proof of integrity.

Table 17:Tiered Evidence Collection Matrix

Responder Level

Available Capability

Evidence Collection Actions

When to Use This Tier

NON-TECHNICAL HRD

No forensic tools available

Physical documentation using a second device camera - photograph the screen showing the evidence, URL bar, and system clock. Record device serial numbers, IMEI, and MAC address manually. Complete paper-based Chain of Custody form.

All HRDs can do this immediately. Provides legally useful documentation even without technical tools.

DIGITAL SAFETY OFFICER

Basic forensic capability

Screenshots with metadata preserved. Email header extraction. Hash computation using CyberChef. Encrypted backup using iMazing (iOS) or ADB (Android). Completion of digital Chain of Custody log.

Appropriate for incidents only require triage. Produces admissible evidence if SHA-256 hash is computed immediately and chain of custody is maintained.

TECHNICAL RESPONDER / HUB

Full forensic capability

Bit-for-bit forensic disk imaging using FTK Imager or Autopsy. RAM capture using Volatility. Write-blocked acquisition. Full Chain of Custody documentation. Hash verification before and after imaging.

Required for incidents that require deep investigation and any case intended for court. Contact Tatua Digital Resilience Centre or KE-CIRT for hub-level response.

If you are a non-technical HRD and a digital incident has occurred: take photographs of the screen using a second device - your personal phone photographing the work phone or laptop screen. Make sure the URL bar, date, and time are visible in every photograph. Write down the make, model, and serial number of the affected device. These simple steps significantly improve the legal usefulness of your documentation.

4.1(b) The Chain of Custody - Every Required Field

Chain of Custody: The chronological documentation showing the seizure, custody, control, transfer, analysis, and disposition of physical or electronic evidence. An unbroken chain of custody is required for evidence to be admissible under Section 106B of the Kenya Evidence Act.

The chain of custody log must be initiated at the moment evidence is first collected and maintained without any gaps through every subsequent transfer, analysis session, and storage event. A single undocumented transfer can be used in court to challenge the entire evidentiary record.

Table 18:Chain of Custody form

Field Name

Description

Example / Guidance

Evidence ID

Unique case reference number

HELP-2026-NBI-001 (format: ORG-YEAR-CITY-SEQ)

Evidence Type

Nature of the digital artefact

Mobile phone, laptop hard drive, email thread, screenshot, USB drive

Hardware Identifiers

Device-specific unique identifiers

Serial number, IMEI (mobile), MAC address, model number

SHA-256 Hash

Cryptographic fingerprint at time of collection

64-character hex string generated using CyberChef or sha256sum immediately upon collection

Collection Date/Time

Exact timestamp with timezone

2026-04-15 14:32 UTC+3 (EAT) - always specify timezone

Collection Method

How the evidence was acquired

Forensic bit-for-bit image using FTK Imager v4.7 / Screenshot with metadata /

Collector Name & Title

Identity of person who collected evidence

Full name and organisational role - not a pseudonym

Collector Signature

Physical or digital signature

Required for Section 106B compliance

Storage Location

Where evidence is stored after collection

Encrypted external drive SN: [XXXX], locked in Room 3B, Organisation HQ

Custodian History

All persons who subsequently handled evidence

Name, title, date/time of receipt, date/time of transfer, reason for transfer, signature

Transfer Signatures

Signed handover for every custody change

Both 'Released By' and 'Received By' must sign at every transfer

Access Log

Record of every access to stored evidence

Date, purpose, person accessing, time returned to storage

4.1(c) Secure Evidence Communication

Currently 82% of Kenyan HRDs report incidents through WhatsApp - a channel that is unsuitable for evidence communication for three reasons: (1) it provides no audit trail, (2) its metadata is accessible to Meta and potentially to hostile actors, and (3) files shared through it lose critical metadata needed for Section 106B compliance.

The transition to professional evidence intake must follow this pathway:

STEP 1 | Immediate intake via Signal

All initial incident reports must be submitted through a designated Signal number or Signal group. Signal preserves end-to-end encryption and is not accessible to third parties. Note: Signal messages themselves are not evidence - they are the intake channel.

STEP 2 | Structured intake via secure ticketing

For organisations with the technical capacity, implement an encrypted ticketing. This creates an auditable, timestamped record of all incident reports. Integrate with your existing playbooks.

STEP 3 | Evidence transfer via encrypted storage

Physical evidence (devices) must be transferred in tamper-evident bags with completed Chain of Custody forms. Digital evidence must be transferred via encrypted storage media - never via email or WhatsApp.

STEP 4 | Archive in access-controlled location

All digital evidence must be stored encrypted, with access restricted to named individuals documented in the Chain of Custody log. Maintain an access log recording every instance of evidence being accessed.

4.3(a) How to Compute a SHA-256 Hash - Step by Step

Using CyberChef ( Web Browser)
  1. Open CyberChef at gchq.github.io/CyberChef
  2. In the 'Operations' panel, search for 'SHA2' and drag 'SHA2' into the Recipe box.
  3. Set the output size to '256'.
  4. Click 'Open file as input' and select the file you want to hash.
  5. The hash appears in the 'Output' box. Copy it exactly.
  6. Record the hash in the Chain of Custody log immediately.
4.2 Navigating Legal Barriers and Local Standards

HRDs operating in Kenya face a complex and sometimes contradictory legal environment. The same laws designed to prosecute attackers can be used against defenders and researchers. Understanding these barriers in advance - and having mitigation strategies ready - is essential for sustainable forensic work.

Table 19:Navigating Legal Barriers and Local Standards

Legal Barrier

Risk to HRDs

Mitigation Strategy

Evidence admissibility under s.106B

Evidence collected without hash verification, proper chain of custody, or from a malfunctioning device may be ruled inadmissible

Always compute SHA-256 hash at point of collection. Maintain unbroken Chain of Custody from collection to court. Document device operational status at time of collection.

72-hour ODPC notification deadline

Missing the notification window creates regulatory liability even if the underlying breach was not the organisation's fault

Designate a named person responsible for triggering the ODPC notification clock and maintaining the notification template in the Jump Kit.

Arbitrary device seizure

Authorities may seize devices under the CMCA without adequate procedural safeguards, destroying evidence and exposing sensitive data

Maintain current off-device encrypted backups. Know your legal rights under the CMCA. Have legal counsel's number memorised. Do not unlock devices under duress.

 CMCA 2018

Provisions of the CMCA intended to prosecute attackers have been used against security researchers and defenders themselves

Document all forensic activities with timestamps and purpose statements. Operate within a formal organisational mandate. Consult legal counsel before any active offensive investigation.

Cross-border jurisdiction

Spyware operators and hosting infrastructure are typically based outside Kenya - legal remedies are limited by jurisdiction

Coordinate with international partners (Citizen Lab, Access Now, Amnesty Tech) who have established legal frameworks for cross-border digital rights cases.

Data protection liability

HROs holding victim, witness, or staff PII without adequate security measures may face ODPC penalties following a breach

Implement data minimisation - collect only what is necessary. Conduct a data audit. Establish formal data retention and deletion schedules.

4.3 Ethical Guidelines and Professional Standards

The ethical framework for HRD forensic work is not a soft consideration appended to technical standards - it is a foundational requirement. Forensic work conducted without ethical discipline can re-traumatise victims, expose them to greater danger, destroy the trust necessary for civil society digital security support networks to function, and produce evidence that is legally and morally tainted. Every technical procedure in this guidebook operates within the ethical framework below.

Table 20:Ethical Guidelines and Professional Standards

Ethical Principle

Standard

Practical Application

Informed Consent

Obtain explicit, informed consent before collecting, storing, or sharing any evidence related to an individual. Explain in plain language what will be collected, who will see it, and what risks sharing carries.

Re-obtain consent before every new disclosure - sharing with a colleague, a forensic lab, or a regulator each require separate consent. Consent given once does not cover all future actions.

Right to Withdraw

The defender has the absolute right to stop the forensic process at any time, for any reason, without justification.

Never pressure or guilt a defender into continuing. If they withdraw consent, stop immediately and discuss what happens to data already collected.

Non-Shaming Principle

Never imply that the victim is at fault. Sophisticated targeted attacks compromise experts. The investigation focuses on attacker infrastructure, not on what the victim did wrong.

Open every engagement with an explicit statement that the attack was not their fault. Redirect all 'how did this happen' questions toward the attacker's methods, not the victim's behaviour.

Minimise Re-Traumatisation

Avoid asking the same questions repeatedly. Avoid requiring the victim to relive distressing events unnecessarily. Work through a trusted intermediary if the victim is too distressed to engage directly.

Collect information once, document it thoroughly, and share internally rather than asking the victim to repeat their account to multiple people.

Data Privacy in Triage

Do not upload files from a targeted attack investigation to public analysis platforms (VirusTotal, Any.Run) without explicit consent and awareness of the risks - the attacker may be monitoring these platforms for evidence their payload has been detected.

Use hash-only lookups wherever possible. If a file must be submitted, strip all metadata first and use a VPN from an isolated analysis environment.

Confidentiality of Investigation

Never discuss a live investigation through channels that may be monitored by the adversary. Use out-of-band encrypted channels (Signal) on separate devices for all coordination.

Compartmentalise information - share only what each team member needs to perform their specific role.

Granting Agency

Give the defender as much control as possible over the investigation. Let them enter their own passwords. Let them approve each step before it is taken.

This is not just ethical - it produces better outcomes. A defender who understands and controls the process is more likely to provide accurate, complete information.

The Tatua Digital Resilience Centre, established by KICTANet, empowers Social Justice Organizations in East Africa to strengthen digital resilience, recover from threats, and harness technology for human rights work. Serving Kenya, Tanzania, and Uganda, it offers strategic support, fosters partnerships, and plans to expand across Africa with sustainable funding models.

Nine Planets, Earth Wing, Suite E9, Kabarnet Garden Road, Nairobi, KENYA | Phone: +(254) 751-000-001 | Email: info@tatua.digital

© 2026 TATUA DIGITAL RESILIENCE CENTRE