The admissibility of digital evidence from open-source forensic tools: Development of a framework for legal acceptance

June 22, 2026

Law enforcement agencies with limited budgets often cannot reach the expensive commercial digital forensic tools, while open-source tools, whose source code is open to inspection and which carry no licence fee, are already technically adequate. Courts nonetheless tend to favour commercially validated tools, because no standardised validation framework exists for open-source alternatives, and this creates an unnecessary financial barrier to high-quality investigation. This study validates and enhances the conceptual framework proposed by Ismail et al. in 2024, comparing two commercial tools against two open-source tools across three test scenarios, each performed in triplicate, with error rates calculated against control references. Properly validated open-source tools produced reliable and repeatable results with verifiable integrity comparable to their commercial counterparts. That matters because United States courts apply the Daubert Standard when deciding whether scientific evidence is admissible, a test that requires a method to be repeatable and to carry a known error rate. The authors therefore set out a framework in three phases designed to bring the use of open-source tools within those requirements.

Research Objectives

- Validate and enhance the conceptual framework of Ismail et al. (2024) so that evidence acquired through open-source tools is legally admissible.

- Compare the capability and consistency of open-source tools against commercial tools in producing forensically sound evidence.

- Address the four factors affecting admissibility: tool capability and availability, evidence reliability and integrity, tool transparency, and the existence of references and standards.

- Develop a framework aligned with the Daubert Standard that practitioners can apply.

Methodology

- Controlled experiments at the Digital Forensic Laboratory of the Pharmacy Enforcement Division, Ministry of Health, Malaysia, using two Windows workstations.

- Commercial reference tools were AccessData Forensic Toolkit (FTK) version 7.5.1.127 and Forensic MagiCube; the open-source tools were Autopsy version 4.19.3 and ProDiscover Basic.

- Three test scenarios: preservation and collection of original data, recovery of deleted files through data carving, and targeted artifact searching in case-specific scenarios.

- Each experiment was run in triplicate to establish repeatability, with error rates calculated by comparing acquired artifacts against control references, following Manson et al. (2007), Flavien (2014) and NIST Computer Forensics Tool Testing standards.

- The Daubert Standard applied here rests on four factors: testability and independent verification, peer review, established error rates, and general acceptance in the relevant scientific community.

Key Findings

- In the first scenario, FTK, Forensic MagiCube, Autopsy and ProDiscover Basic all produced forensic images with identical MD5 and SHA1 hash values across all three runs and extracted the same 175 artifacts (126,489,439 bytes) each time, with no errors found. ProDiscover Basic completed the task in less time.

- In the second scenario, Autopsy recovered 112 deleted files (138,018,816 bytes) from every image with no errors, matching the commercial results.

- In the third scenario, Autopsy located the target file m57biz.xls and verified its hash value with no errors, again matching the control.

- The limits lay with individual tools rather than with open source as such: ProDiscover Basic could not recover deleted data, so recovery had to be completed in Autopsy, and it could not complete the third scenario because its documentation restricts it to .EVE and .DD image formats.

- The authors conclude that the results satisfy the Daubert Standard on repeatability, methodological transparency and minimal error rates, and present a three-phase framework covering basic forensic processes, result validation, and organisational digital forensic readiness.

Recommendations

- Resource-constrained organisations can run forensically sound investigations with open-source tools without compromising admissibility, provided the tools are validated under this framework.

- Evidence should be validated through repeated testing before court presentation, which the authors identify as a critical gap in current digital forensic practice.

- Tools should be matched to the investigation scenario and to organisational expertise, since capabilities differ between tools and teams with experienced staff are better placed to exploit open-source options.

- Future work should develop jurisdiction-specific implementation guidelines and extend validation to emerging scenarios, particularly Internet of Things devices and cloud environments.

- The authors state their own limitation: the framework validates results primarily through repeatability rather than full reproducibility, which they mark as an area for future research.

Key Takeaways

- The legal obstacle facing open-source tools is not technical quality but the absence of a standardised validation framework; once that framework is in place, the experiments show open-source results matching commercial ones.

- Identical hash values across repeated tests are what demonstrate that evidence has not been altered, and what make an examination auditable.

- For Thailand the study speaks directly to agencies working under budget constraints, since Autopsy carries no licence fee. This connection is our own; the study was conducted in Malaysia and refers to a United States court standard.

References

Ismail, I., & Zainol Ariffin, K. A. (2025). The admissibility of digital evidence from open-source forensic tools: Development of a framework for legal acceptance. PLOS ONE, 20(9), Article e0331683. https://doi.org/10.1371/journal.pone.0331683

Full text (Open Access): https://journals.plos.org/plosone/article?id=10.1371/journal.pone.0331683