SakshyaYantra Forensics Bible
The forensic family handbook · plain English, court-accurate

Everything the SakshyaYantra Forensic Suite and Mobile Workbench can do, every evidence type, every step in the published order, with the standard behind it and the honest limit stated. Written so a first-week examiner can follow it and a court can rely on it.

2Forensic products
36Case-workbench workspaces
17Evidence source types
10Steps, one order
Scroll
How to read this Bible

Five kinds of box, one promise

Every section is built the same way, so you always know where to look. Best practice comes first, then what to select, then the numbered steps in the order they are published. GUI and command line, then the options, the things to weigh, the standards, and the limits. Watch for these five markers.

Best practice

The right thing to do, taken from the forensic checklist the product itself teaches. Do this by default.

!Weigh this

A choice that costs time, space or defensibility. Not a rule, a thing to decide on purpose.

§Standard

The published practice a step satisfies. ISO/IEC 27037, NIST SP 800-86, ACPO, SWGDE, ISO/IEC 27042, BSA 2023 s63(4). Cited from the product, never invented.

Honest limit

What the tool cannot do, and where the real ceiling is. A section that states none is claiming a certainty it does not have.

Do

  • Every section carries a green Do list, the practices that keep the evidence defensible.

Don't

  • And a red Don't list, the real mistakes that ruin a case, taken from the product's own "not this" guidance.
§On screenshots

Every Real app image is a genuine capture of the shipping application (an empty state is shown honestly as empty). Every Illustration image is a rendered picture of the objects the work involves, never a faked screen, never fabricated evidence or a fabricated device.

The forensic family

Two products, one engine, one brand

SakshyaYantra, sakshya, evidence, after the Bharatiya Sakshya Adhiniyam 2023, is the forensic family. Data recovery is a separate family (RecoverYantra) so the two never pollute each other. Here are the two forensic products and exactly what each contains.

Product code 10 · the superset

SakshyaYantra Forensic Suite

Evidence, from the disk to the courtroom.

The whole forensic platform: verified imaging, artefact analysis and the super-timeline; the fleet, an agent pushed to endpoints, live acquisition of machines that cannot be switched off, sweeps and authorised cloud acquisition; and video evidence, footage decoded through the recorder registry, reviewed frame-exact, redacted under typed review, enhanced in a recorded processing graph, examined for authenticity, and exported with the draft Section 63(4) certificate.

For: examiners, investigators, incident response and forensic laboratories, from a police unit to an enterprise fleet.

forensicsgallerygeotimelinememorylinkhashsetkeywordingestyaraviewstegocasehubcrosscasecasequeryrecorderscctvdronerobotvehicleemaildatabaseremotecloudraidnandrecondetectimagingrecoveryfootagereviewredactmedialabauthenticityplateexport
The mobile front door

SakshyaYantra Mobile Workbench

Acquire the phone as evidence.

Forensic mobile acquisition: identify the device, run the method that reaches it (checkm8, Qualcomm EDL, MediaTek BootROM, rooted ADB, backup), acquire byte-exact under a recorded authority, and seal it into the case with the chain of custody and the draft Section 63(4) certificate. It hands the acquisition to the Forensic Suite for deep examination.

For: examiners and forensic laboratories acquiring mobile evidence.

mobilephoneimagedetectforensicscasehubstego
The division of labour

The Workbench acquires and seals. The Suite examines. A recovery-family cousin (RecoverYantra Mobile) does the same acquisition for the consent / data-loss case, but only the forensic Workbench adds the evidentiary wrapper, the sealed manifest, the certificate, the case lock.

The spine of every case

The examination, one order, ten steps

A recovery job optimises for getting the most data back. A forensic job optimises for being able to prove what was done to get it, so the order is different, and the order is the point. This is the sequence the product teaches (recoveryantra steps forensics), and it is the same order EnCase, FTK, X-Ways and AXIOM present. Press play and let it walk you through, or click any step.

§Why verify sits in the middle

Verification is step 6 of 10, between acquisition and analysis, not at the end. Analysing an unverified image means every finding rests on a copy nobody checked. This single ordering is what makes everything after it defensible.

Best practice, before anything else

Seven habits that hold up in court

These come before the steps in every section because they are what the steps exist to protect. Learn them once; they apply to every evidence type below.

Choose at the door

Offline, local AI, or cloud, decided per case

AI is optional to the customer and present in every build, in three modes. The mode is chosen when the app and the case are opened. For police work the default is offline. Whatever you pick, the examiner's own reading is sealed before any AI answer is shown, and every digest that leaves the machine is on a transfer manifest.

Mode · none

Fully offline

No model, no internet, nothing leaves. The examination stands entirely on the methods and the examiner. The safe default for seized evidence.

Mode · local pack

Local model pack

A signed model pack runs on the bench with no internet. You get model observations air-gapped; the pack version is recorded with every observation.

Mode · cloud

Authorised cloud

Per-agency authorisation switch, off by default. Reachability is tested first, keys live in the OS credential store, and a transfer manifest lists every frame digest that left.

Do

  • Pick the mode when you open the case, and record it, offline for anything seized unless authority says otherwise.
  • Run "Test connection" for cloud before you rely on it; it is a real round trip, not a guess.
  • Treat every model answer as an observation, promoted to a finding only by a typed reviewer decision.

Don't

  • Don't send anything to the cloud without the agency authorisation switch on and the authority recorded.
  • Don't send the video, the frame pack is the only unit that leaves the machine.
  • Don't quote a model's verdict as the finding. The methods and the examiner make the finding.
Evidence by source

Start from what is in front of you

The examination order above is the same for every exhibit. What changes is how you acquire it and what it can give back. Pick your source. Sources that acquire the same way are grouped; each section notes where the evidentiary wrapper (sealing, certificate, custody) applies.

Illustration: a digital-forensics lab bench, an opened hard drive on a write-blocker, a seized phone in an evidence bag, an analysis laptop
Illustration A forensic bench: the exhibit, the write-blocker, the analysis station. The bench is the same; the exhibit decides the acquisition.
Examine the verified copy

The examination toolbox

Once you have a verified image, the analysis runs across many workspaces, and everything you do is written to the hash-chained audit trail as you do it. Each tool below is a real workspace with a real command. They are the "Examine" step of the ten, opened up.

The super-timeline workspace: a filter by artefact kind and a plotted timeline
Real app The super-timeline, filter by artefact kind, plot, mark and export. Shown on the synthetic bench corpus, which has no dated OS artefacts, so it is honestly empty.

Do

  • Corroborate a finding across several artefacts, recycle bin, USN journal, prefetch, registry, LNK, event logs, jump lists, shellbags, AmCache, browser history.
  • Let the audit trail record each step as you take it; seal it at the end.
  • Use hash sets to set aside the known (operating-system files) and surface the unknown.

Don't

  • Don't rely on one artefact. A single trace is a lead, not a conclusion.
  • Don't examine the original machine, work from the verified image, or every finding rests on something that has since changed.
  • Don't leave the audit trail unsealed; a chain cannot detect a tail that was cut off.
Video evidence

From a recorder export to a certified still

Video is its own pipeline, and it has its own hard rules. Footage comes in through the decode ladder, is reviewed frame-exact, redacted under a named reviewer, enhanced in a recorded processing graph, examined for authenticity, and exported with hashes and the certificate. Nothing but a frame pack ever leaves the machine.

Footage
decode ladder
Review
frame pack
Redact
typed review
Enhance
recorded graph
Authenticity
every method
Export
+ certificate
The three times are never merged

A recorder gives you three different clocks and they must stay in three different fields. Merging them is how a timeline lies.

Presentation time (PTS)

The decoded stream's own ticks and time base. Exact, machine-truth, but relative to the recording, not the wall clock.

Overlay clock

The time the recorder burned onto the picture. Carried as text, because that is all it is, the recorder's clock, which may be wrong.

Case time

The real-world time of the event, a separate field with its own uncertainty and your stated clock assumptions.

The enhancement lab: classical recipe cards and an AI track, original beside enhanced
Real app The enhancement lab, classical recipes and an AI track kept apart, original always beside enhanced, the processing chain printed beneath.
§Authenticity, authenticate

The examine verb runs every method over a clip: structure, codec history, double compression, frame statistics, optional model packs, and camera identification by PRNU (authenticate <file> --camera-reference img1 img2 … --tool prnu_identify). It reports a ranking, one score convinces nobody, and a model output is an observation, not the finding.

Repair unplayable video, fixvideos

Where a recovered clip will not open, recoveryantra fixvideos <folder> repairs the structure of the videos in a folder so a player can read them. It repairs structure, not lost picture data, a clip whose media is genuinely missing is flagged, never faked whole.

Do

  • Copy and hash the export before you touch it, the intake does both.
  • Capture a frame pack (each frame with its PTS, decoded index, overlay text, source hash and its own SHA-256) for anything the court needs to see.
  • Keep the enhanced frame beside the original with the recipe chain printed; export both.
  • Let a named reviewer approve every redaction and every promotion.

Don't

  • Don't re-encode a recorder export with a converter first, the converter's frames are not the recorder's frames.
  • Don't play evidence off the pen drive it came on; copy and hash it first.
  • Don't send a screenshot or a player snapshot, it has no time base, no hash, no chain.
  • Don't write the overlay clock down as the time of the event.
AI, on a leash

An AI answer is an observation, never a finding

AI is present in every build and optional to the customer. The rule that makes it safe is the order: the examiner's own reading is sealed before any AI answer is shown. An AI response is recorded as an "AI observation", model, version, prompt, input hashes, time, and its verbatim text, labelled as such, and promoted to a finding only by a typed reviewer decision.

Plate assistance: seal your own reading, then read the model's answer
Real app Plate assistance, your own reading is sealed first, then the model's observation is revealed beside it (honest empty: no plate model pack loaded on this bench).
Ask-the-case: retrieval list and a sealed verdict track
Real app Ask-the-case, a retrieval question over the case, with your reading sealed before the model's words are revealed.

Do

  • Seal your own reading first, the workspace makes you.
  • Keep the whole observation record: model, version, prompt, input hashes, time, verbatim text.
  • For cloud mode, keep the transfer manifest of every digest that left.

Don't

  • Don't show or read the AI answer before your own reading is sealed.
  • Don't promote an observation to a finding without a typed reviewer decision.
  • Don't send the source media, only the frame pack, only its digests.
From the bench to the court

The report, the certificate and the sealed trail

The report carries the findings, the method, the tool and its version, every hash, the source offset of each recovered item, and, not optional, the limits of what the examination can support. India's electronic-evidence rule is served directly: the draft Section 63(4) certificate under the Bharatiya Sakshya Adhiniyam 2023. Then the audit trail is sealed and the exhibit is signed back in.

The report builder in the case workbench
Real app The report builder, findings, method, tool version, hashes and stated limits.
Export and the Section 63(4) certificate builder with a case open
Real app Export with the draft Section 63(4) certificate for electronic records.
Illustration: a wax-sealed document, a balance scale and a rising green fingerprint, the chain of custody and the courtroom
Illustration Custody unbroken from seizure to disposal; the certificate is what carries an electronic record into court.
Prove it, do not promise it

"Read-only" is measured, not asserted: the source is fingerprinted before and after every job and the report states which regions were checked. Run the tool's own validation (recoveryantra validate) against images whose contents are known, and check the trail is unbroken including anything cut off the end (recoveryantra audit <case> --manifest <manifest.json>).

Do

  • State the limits, a report that states none is claiming a certainty it does not have.
  • Seal the audit trail; the receipt goes into the manifest, which is what catches a later truncation.
  • Draft the certificate from the case: recoveryantra certify draft --case <folder> -o <file>.

Don't

  • Don't rely on "the tool is read-only" as your answer, measure it and put the measurement in the report.
  • Don't leave the audit trail unsealed.
  • Don't overstate. An observation is not a finding; a possible reading is not a certainty.
The rules behind the steps

Standards this product follows

These are the published practices the workspaces cite, pulled from the product's own step guidance, not added for show. When a step names a standard, this is what it means.

StandardWhat it governsWhere it shows up here
The ceiling, stated

What this cannot do, and says so

The honesty boundary is the most important rule in the whole product. A capability is never faked and a result is never fabricated. Where a device or a method cannot be reached, the tool says which method would and what it needs, rather than pretending. Four ceilings worth carrying in your head:

Modern mobiles

Public exploits reach real devices: checkm8 covers A11 iPhones and older. A current flagship after first unlock, and A12+ / FBE-BFU Android, often has no public software vector, the plan says so and names the licensed package that would reach it, instead of guessing.

Ingested dumps

We parse and reconstruct dumps a rig produced (chip-off NAND, foreign forensic containers, a pro imager's image + bad-sector map). We do not do physical chip or live-bus capture, that is a hardware-rig ceiling, stated plainly.

Authority

The operator's authority or consent is recorded, not verified. The tool never asserts ownership; it records what the operator states, and the record travels with the evidence.

Enhancement

Enhancement reveals what is already there; it never invents detail. A blurred plate that no method can resolve stays unresolved, with the method and uncertainty stated beside the result.

Appendix

Command reference, utilities

A handful of commands sit beside the workflows above rather than inside them, housekeeping and orchestration you reach for now and then. They are listed here so the reference is complete without cluttering the case flow.

CommandWhat it doesTypical use
§Two commands you will use in every case

recoveryantra steps forensics prints the ten-step examination order with its standards and safety gates, the same order this Bible is built around. recoveryantra which "clicking noise" answers "what is my situation called and which feature do I need", in your own words, before you start.