HARCFL logo Heart of America RCFL
Regional Computer Forensics Laboratory Regional Computer Forensics Laboratory
 Click for Program Click for operations Click for Legal Click for news & information Click for training room Click for links  
Click for service request
Click for home page
Click for contact information
Click here to go to the RCFL Speakers Bureau
Click here to complete our Customer Satisfaction Survey.

Service Request Instructions



PLEASE READ ENTIRELY BEFORE SUBMITTING YOUR REQUEST

1) Prior to submitting evidence, you must complete an on-line submission request. Acceptance of said requests will be evaluated on a case by case basis by the HARCFL Director or designee.

2) If approved, you will receive an email of confirmation. Do not submit evidence until you receive a reply.

3) Upon submitting evidence, you will need to bring the following items:

  1. Copy of legal authority (consent, search warrant, etc) NO ORIGINALS
  2. Copy of investigative reports with sufficient detail to conduct examination
  3. NON-PARTICIPATING AGENCIES ONLY: Letter from Chief/Sheriff etc on department letterhead. (The template is linked below. All bold text must be included. Italicized language should be edited to reflect the current specific case.)

Intake guideline:

  • The HARCFL will only accept cases on Felony offenses and matters of National Security.
  • The HARCFL will only examine media that is reasonably believed to contain evidence. Submissions exceeding 5 items or 3 TB’s must be previewed prior to submission.  The HARCFL does not “screen” media for the presence of contraband.
  • Floppy disks should be previewed by opening the write-protect tab prior to insertion into workstation. Unpreviewed floppy disks will not be examined.
  • CD, DVD’s and BD media should be previewed in a ROM drive. Unpreviewed optical media will not be examined.
  • Hard drives and related media should ONLY be previewed by using write-blocking software and/or hardware. 
  • Cell phones and loose media should be examined in the HARCFL self-service kiosk before submission.

 

Requested Services

You must specifically list what the examiner should extract from the media during the course of the examination. Please provide as much case information as known to include names, user names, dates of offense, and software in use.  Without detailed information on the case and what is needed, the examiner is unable to conduct the exam.

The following requests will not be accepted:

  • “Extract all data possible”
  • “Examine for child porn”
  • “Extract suspicious information”
  • “Dump all contents of drive”

Examples of appropriate requests:

  • “Examine for evidence of possession and distribution of child pornography on Limewire. Username of JoJoNasty. Child pornography pictures and videos were downloaded on May 1, 2010”
  • “Extract address book, SMS, call logs, pictures and videos depicting a young female”
  • “Determine usage of computer on November 12, 2010 on or about 0200 hours. Victim found shot to death. Believe to have been contacting prostitutes using Craigslist and Backpage”.
  • “Extract data in reference to check fraud investigation. Suspect used account numbers of 12345 and 6789 written to Sarah Rouse and Joe Davis. Suspect named Ima Thief. Determine number of checks written”
  • “Extract Internet history for the account John Doe from March 5th to March 31st, 2010” 

 

Continue to Service Request Form