DIGITAL EVIDENCE HANDOFF RECORD Purpose: Give an authorized responder useful observations and custody context. Complete what is known; label uncertainty. Do not collect new material, search personal devices or alter evidence merely to fill this form. Follow the incident lead's instructions and obtain appropriate authority before collection. CASE AND AUTHORITY Private case reference / coordinator / trusted contact route: [ ] Investigation question and business impact: [ ] Authorized scope / approver / legal or preservation instructions: [ ] Responder and agreed next step: [ ] OBSERVATION Observed date / time / time zone; estimated or exact: [ ] Observer and what they directly saw: [ ] Device or service / tenant / account / private inventory reference: [ ] Exact visible alert or event reference: [ ] Interpretation or hypothesis, kept separate from observation: [ ] Known log-retention deadline / unknowns: [ ] ITEM RECORD (repeat for each item) Item identifier / description / source: [ ] Original, preserved copy or working copy: [ ] Collected by / authority / date / time zone / method: [ ] Tool and version, if supplied by the examiner: [ ] Hash algorithm and digest, if supplied; exact item hashed: [ ] Protected storage location / access owner: [ ] Handling limitations or gaps: [ ] CUSTODY AND ACTION LOG (repeat each row) Date/time/zone | person | item | action or transfer | purpose | result [ ] Recipient acknowledgment / receipt reference: [ ] Previously performed containment, scans, restarts, copies or cleanup: [ ] HANDOFF CHECK [ ] Observations distinguished from conclusions. [ ] Prior actions and uncertainty recorded. [ ] Originals and working copies distinguished. [ ] Recipient, authorized transfer method and acknowledgment confirmed. [ ] Follow-up owner and deadline assigned; credentials handled separately. Source context: NIST SP 800-86 (2006), NIST SP 800-61r3 (2025), and CISA ransomware guidance linked in the guide. This record does not certify legal admissibility or replace a qualified examiner's acquisition procedures. Yenra | Updated September 9, 2026 Guide: https://yenra.com/computer-forensics/