A recurring space for discussion, knowledge exchange, and deeper understanding of the evolving challenges at the intersection of technology and law.
Each edition moves through a fixed rhythm — from open submissions to a published answer to community discussion. Here's where the week stands.
The CyJurII community submits questions through the dedicated Q&A platform below.
A selected question is answered in that week's edition of the Expert Q&A Series by Justyna Sarkowicz.
The edition is shared across CyJurII channels, including social media and the CyJurII website, inviting discussion and new questions for next week.
Questions on any area of cyber law are welcome — these themes are a starting point, not a limit.
Submissions are reviewed each week. Selected questions are answered on Friday and credited by first name unless you ask to remain anonymous.
Every published edition, in order. New editions are added each Friday.
Volatile-memory forensics focuses on capturing and interpreting RAM contents before they disappear due to a system shutdown, reboot, or power loss. The main techniques and tools can be grouped into four key stages: 1. Live RAM acquisition: The first priority is to create a forensic binary image of physical memory while the system is still running. The following techniques are commonly used: a) Direct physical-memory acquisition using a trusted acquisition utility running in user space. b) Kernel-based acquisition, utilizing a dedicated driver to access physical memory.c)Hypervisor-based acquisition for virtual machines. d) Hardware-based acquisition using DMA (Direct Memory Access) controllers in specialized laboratory environments. It should be noted that RAM capture must occur before the computer is shut down or rebooted, as volatile artifacts can be permanently lost or modified rapidly. Commonly used tools are Magnet RAM Capture, Belkasoft RAM Capturer, WinPmem / DumpIt, LiME (Linux Memory Extractor) – requires loading a Linux kernel module, and AVML (Acquire Volatile Memory for Linux) – a modern, static tool written in Rust by Microsoft that does not require kernel module compilation. The resulting image is immediately hashed (generating a checksum) and preserved as evidence. The entire process, tool versions, and acquisition circumstances are strictly documented. 2. Memory-image analysis The investigator conducts the analysis on the preserved image rather than repeatedly interacting with the live system to avoid tampering with evidence. The industry standard framework is Volatility 3, which can identify Running and terminated processes (along with their command lines, Loaded DLLs and kernel modules, Active network connections and open sockets, Open files and handles, Registry-related artifacts, Injected or hidden code, as well as kernel structures, and Credentials and authentication material left in memory. Other solutions include commercial forensic suites such as Magnet AXIOM and Belkasoft X (the Rekall framework was used in the past but is now considered an archived/legacy project). 3. Recovering non-persistent evidence RAM contains critical information that may never be written to the hard drive. Investigators search the memory image for: a) Network evidence: IP addresses, active connections, DNS cache, connection states, and remnants of network communications. b) Application evidence: web browser activity traces, chat/session logs, application credentials or tokens, clipboard contents, and recently processed documents. c) Malware evidence: injected processes (process injection), reflective DLLs, unpacked malicious code, encryption keys, and C2 (Command and Control) server configurations. d) System evidence: logged-in users, command history, loaded modules, and OS kernel objects. 4. Correlation and validation Memory artifacts are rarely interpreted in isolation. RAM analysis findings are correlated with: a) Hard drive forensic images and operating system logs. b) Browser history and network log files (firewall, proxy, PCAP). c) Cloud service provider logs. Validation is crucial because RAM is a dynamic environment. The acquisition process itself is intrusive and modifies the target computer's memory content (known as the observer effect). Therefore, investigators meticulously document the dump method, system state, hashes, timestamps, and the full chain of custody. 5. Significance for electronic evidence admissibility From a legal and procedural perspective, the critical aspect is the entire lifecycle of the evidence: a) Live system → RAM acquisition → Forensic image → Integrity verification → Analytical processing → Interpretation → Documentation → Preservation. b) The specific nature of volatile memory lies in its temporal fragility. Unlike traditional data stored on hard drives, failing to acquire RAM before powering off the device results in the permanent loss of vital evidence..
Yes. The use of cryptographic hash functions and electronic timestamps forms the foundation of modern digital forensics and is a key element in ensuring the integrity of digital evidence. In the era of widespread digitalization, a critical challenge for law enforcement agencies and the judiciary is to demonstrate that electronic evidence has not been modified (either intentionally or accidentally) from the moment of its seizure to its presentation in court. A) TECHNICAL AND PROCEDURAL STANDARDS The data preservation process relies on international standards, among which the publications of the American National Institute of Standards and Technology (NIST) and ISO standards play a pivotal role. 1. ISO/IEC 27037: This international standard defines guidelines for the identification, collection, acquisition, and preservation of digital evidence. According to the standard, the calculation of the hash value must occur immediately after creating a forensic copy/image of the storage media. 2. NIST SP 800-107 Revision 1: The NIST recommendation explicitly highlights the necessity of using cryptographically strong hash functions. The SHA-256 (Secure Hash Algorithm, 256-bit) function is currently the market standard, replacing collision-prone and obsolete MD5 and SHA-1 algorithms. NIST points out that SHA-256 provides a sufficient level of resistance against data forgery attempts by generating a unique, 64-character hexadecimal string for each unique set of input data. The practical application of these standards is illustrated by the process of securing a smartphone containing communication history (e.g., from the WhatsApp application). Performing a bit-stream image (forensic copy) of the device's memory and instantly hashing it with the SHA-256 algorithm creates a so-called "digital fingerprint." Any subsequent attempt to edit even a single bit of data (e.g., changing a message date, deleting a character) will irreversibly change the resulting hash value, demonstrating a lack of file integrity (known as the avalanche effect). B) ELECTRONIC TIMESTAMPS IN LIGHT OF COUNCIL OF EUROPE GUIDELINES AND eIDAS Computing the hash value alone only proves that the copy has not been altered since it was hashed. However, it does not allow for independent verification of exactly when this process took place. To address this issue, digital forensics implements the mechanism of Trusted Timestamping. Council of Europe Guidelines: In its recommendations on electronic evidence (including Electronic Evidence in Civil and Administrative Proceedings), the Council of Europe explicitly identifies timestamping as a mechanism confirming two key circumstances: data integrity and its existence at a specific point in time. eIDAS Regulation: Under European law, a qualified electronic timestamp (compliant with the eIDAS Regulation) binds the date and time with the data (in this case, with the SHA-256 hash) in a manner that rules out the possibility of undetectable data modification. It is issued by an independent, trusted third party (Certificate Authority), which gives it powerful evidentiary value before courts across the European Union. C) INTEGRITY VS. AUTHENTICITY – EVIDENTIARY BOUNDARIES In judicial proceedings, it is crucial to distinguish technical terms from legal concepts. The consistency of the SHA-256 hash value (re-hashing performed prior to analysis or presentation in court) confirms solely the integrity of the file. 1. What a hash proves: It confirms that the file examined by the forensic expert in court is bit-for-bit identical to the file secured by the police/prosecution at the scene. This rules out allegations of evidence tampering by law enforcement authorities. 2. What a hash does not prove: Hash consistency does not determine authenticity (whether the defendant is truly the author of the message, or if someone else logged into their account), the legality of obtaining the evidence (whether the seizure complied with criminal procedure), or its probative value (whether the content of the conversation is true, or if it was, for example, a joke or a provocation). These elements are subject to the free evaluation of evidence by the panel of judges. D) CHAIN OF CUSTODY Cryptography does not operate in a vacuum. Hash values and timestamps form the technological core of a broader procedure known as the Chain of Custody. Full documentation of the digital evidence history must include: 1. Personal data: Who secured the media and who had access to it. 2. Methodology: What hardware tools (e.g., write-blockers) and software tools were used. 3. Chronology: The exact time of each operation, secured by the aforementioned timestamp..
Contemporary discussions about the evolution of human rights in the age of the internet and emerging technologies need not focus on creating an entirely new catalogue of digital rights. In my view, the key challenge is to reconsider how existing legal concepts are understood and applied. Traditional safeguards must be adapted to a new reality in which technological progress has fundamentally altered the balance of power, particularly by reshaping the relationship between individuals, states, and powerful private actors. In the data-driven economy, the traditional understanding of the right to privacy is increasingly insufficient. Historically, privacy was largely understood in terms of protecting the home, correspondence, and the private sphere from unwanted interference. Today, effective privacy protection must also encompass meaningful control over personal information and the ways in which it is collected, combined, profiled, and processed at scale. Freedom of expression is undergoing a similar transformation. Its exercise increasingly takes place within privately operated digital environments, where algorithms influence which information is amplified, recommended, or made less visible. Through often opaque systems of content moderation, ranking, and promotion, digital platforms can therefore have a significant impact on the conditions under which public discourse takes place. Perhaps the most fundamental challenge, however, concerns human autonomy. Artificial intelligence systems are increasingly capable of analysing behaviour, generating risk profiles, predicting preferences, and influencing individual choices. Under these conditions, the boundary between technological assistance and unacceptable interference with individual autonomy becomes increasingly difficult to define. This issue is particularly significant in the justice system, where the use of algorithmic tools may directly affect due process, judicial decision-making, and the position of the individual before the law. Consequently, I believe the focus of the academic debate should shift. Rather than asking only whether we need new rights, we should also ask whether existing human rights remain genuinely effective in the digital environment. The future of human rights protection will not depend solely on adopting new declarations or creating new legal categories. It will depend on ensuring that existing rights remain enforceable in practice. There is a real risk that rights may retain their formal validity while gradually losing their practical significance. The digital age therefore may not require a revolution in human rights law. It requires something more fundamental: a renewed understanding of how existing rights must be interpreted and protected in an environment increasingly shaped by automated decision-making and complex technological systems. Ultimately, the central question is not simply what new rights we should create, but whether we can preserve meaningful human agency in a world where technology increasingly shapes the decisions that affect us.
[In my opinion, one of the greatest challenges associated with evidence generated or modified by AI in criminal proceedings is determining its origin, integrity, and credibility, and the ability to reliably verify it. The problem, however, is not limited to deepfakes. AI can create new materials, but it can also modify authentic images, recordings, documents, or other digital data. Therefore, determining where the material originated, how it was obtained, whether it was modified, and what happened to it during subsequent stages of processing becomes crucial. In this context, provenance and chain of custody become particularly important. At the same time, authenticity is not the same as credibility. Confirming the source or integrity of the material does not necessarily mean that its content accurately reflects reality or that it has been correctly interpreted. Therefore, assessing AI-enabled evidence should go beyond the mere question of whether AI was involved in its creation or processing. We should therefore neither automatically trust AI-enabled materials nor reject them on this basis. We need clear, technologically neutral, and practically applicable standards of evaluation that will allow courts to assess the origin, integrity, processing, and credibility of specific evidence. In my opinion, the most important question today is not: "Did AI contribute to the creation of this evidence?" but: "Can we verify its history and properly assess its probative value?" This is particularly important because AI poses two opposing threats: the acceptance of manipulated evidence as authentic and the wrongful denial of authentic evidence as allegedly generated or manipulated by AI.