Standards-aligned operator training
Eight modules across the four phases of NIST SP 800-86, from preparing the bench to disposal. Each states the standard it follows, what you must have before starting, what you do with this product, what it produces for the case file, and where that module stops.
What this training is, and what it is not
RecoverYantra follows the published guidance listed below. It is not certified, accredited or approved by any of those bodies, and neither is this course. Following a standard and being certified against it are different claims, and only the first is made here.
The validation harness built into the product is modelled on the NIST CFTT test specifications and is not a CFTT certification; every report it writes states that. Whether a particular court, regulator or insurer accepts a given result is their decision, not a property of the software.
What each one governs
Every citation in the modules below points at one of these. Nothing is cited that is not listed here, and a test enforces it.
| NIST SP 800-86 | Guide to Integrating Forensic Techniques into Incident Response The four-phase model this curriculum follows: collection, examination, analysis, reporting. |
|---|---|
| NIST SP 800-88r1 | Guidelines for Media Sanitization Defines Clear, Purge and Destroy, and states that a single overwrite pass is sufficient on modern media. |
| ISO/IEC 27037 | Identification, collection, acquisition and preservation of digital evidence The international handling standard: what a first responder does, and the order they do it in. |
| ISO/IEC 27041 | Assuring suitability and adequacy of incident investigative method Why a tool has to be validated for the use it is put to, and how that assurance is demonstrated. |
| ASTM E2916 | Standard Terminology for Digital and Multimedia Evidence Examination The vocabulary. Using the terms consistently is what makes a report reviewable by somebody who was not there. |
| ASTM E3016 | Standard Guide for Establishing Confidence in Digital and Multimedia Evidence Forensic Results by Error Mitigation Analysis Requires that the ways a result can be wrong are identified and addressed, rather than assumed away. |
| SWGDE | Scientific Working Group on Digital Evidence, best practice series Practitioner-level best practice for acquisition, examination and reporting. |
| NIJ Digital Evidence Guides | US Department of Justice / National Institute of Justice Field guidance for first responders and investigators. |
| FRE 702 | Federal Rules of Evidence, Rule 702: testimony by expert witnesses Requires reliable principles and methods, reliably applied to the facts of the case. |
| FRE 902(14) | Federal Rules of Evidence, Rule 902(14): self-authenticating certified data copied from an electronic device A copy authenticated by a hash-based process, certified by a qualified person, is self-authenticating. |
| NIST CFTT | Computer Forensics Tool Testing programme The test specifications the product's own validation harness is modelled on. The harness is NOT a CFTT certification. |

What you must have first
- A machine that is not also the destination for case data
- Storage for images and output, sized for the largest exhibit expected
- A hardware write blocker where one is available
- A record of the product version this bench is running
What it produces for the case file
- The dated validation report, kept in the quality records
- The product version recorded against the case
What you do
- Record the version and validate the buildRun on a new bench and after every version change. The harness runs the SHIPPING engine against known ground truth and writes a dated report.
recoveryantra validate --out E:\Quality\<date> - Check what acquisition methods are actually available hereA method with no tool installed on this machine is not available, however the case is authorised.
recoveryantra capabilities --tools - Set the working mode deliberatelyForensic mode hashes every item and writes the custody manifest. It must be set before the scan, not after.
recoveryantra mode forensic
Why it matters
ISO/IEC 27041 asks how you know the method is suitable for the purpose. A dated validation report against known ground truth, from the same build that did the work, is the practical answer.
Limits of this module
- The validation harness is modelled on the NIST CFTT specifications and is NOT a NIST certification. Every report it writes says so, and it must be described that way.
- Validating the tool says nothing about the examiner's competence, which FRE 702 also reaches.
Hit one of these limits? The situation chooser names the product or the method that gets past each one, case by case.
Module 2: Establish and record authority

What you must have first
- The lawful basis in writing: warrant, consent or statutory power
- The scope that basis actually covers
- The examiner's name and organisation
What it produces for the case file
- Operator, authority, organisation and case reference in the audit trail from the first action
What you do
- Record the authority on the acquisition itselfRecorded at acquisition, so every later artefact carries the same reference. Added afterwards, the earliest entries carry a different one.
recoveryantra acquire -o E:\Case\Ex1 --operator "<name>" --authority warrant --org "<organisation>" --case <ref> - Record an advanced-method decision separatelyMethods that can alter a device are off until an examiner opts in, and the choice goes into the audit trail with the case.
recoveryantra capabilities --enable <method> --operator "<name>" --case <ref> - Check what has been acknowledged on this installUseful when auditing a shared bench.
recoveryantra legal --status
Why it matters
The field records the assertion of authority. It does not create authority, and it is not legal advice. What it does is make the basis and the person asserting it part of the record from the first action.
Limits of this module
- Recording an authority does not make an unlawful acquisition lawful.
- Scope matters as much as basis: an authority covering one device does not extend to another that happens to be present.
Hit one of these limits? The situation chooser names the product or the method that gets past each one, case by case.

What you must have first
- The exhibit, labelled and photographed as received
- A sterile destination with room for the whole source
- A decision on retry policy, made before the first read
What it produces for the case file
- The verified image and its hash
- The acquisition record: who, when, under what authority, with what write-blocking
What you do
- Triage before touching anythingCondition, connection and device class. This is what decides between reading directly and imaging, and on an audibly failing drive it should be brief.
recoveryantra list --triage - Engage a write blockWhere no hardware blocker is available. It is an operating-system measure and must be reported as a software block, not a hardware one.
recoveryantra acquire -o E:\Case\Ex1 --write-block - Image to an evidence container and verifyE01 carries the acquisition metadata other tools expect. The image is hashed on read and verified on completion.
recoveryantra image --device <dev> -o E:\Case\Ex1\disk.E01 --format e01 --retries 2 - If the machine is running, capture memory before the diskMemory cannot be captured after shutdown, so isolate the machine from the network WITHOUT powering it off and take memory first. RecoverYantra ANALYSES the resulting image with this command; the capture itself is made with your own acquisition tool, and which one you used belongs in the record.
recoveryantra memory info E:\Case\Ex1\memory.raw
Why it matters
FRE 902(14) treats a copy authenticated by a hash-based process and certified by a qualified person as self-authenticating. The hash recorded at acquisition and verified afterwards is what that rule rests on, which is why verification is not optional.
Limits of this module
- A software write block is not equivalent to a hardware write blocker, and the report must not describe it as one.
- Physically damaged media needs a cleanroom before it can be acquired at all. The product says so rather than attempting it.
- RecoverYantra does not capture live memory. It analyses a memory image captured with another tool, and the acquisition tool used should be named in the record.
Hit one of these limits? The situation chooser names the product or the method that gets past each one, case by case.

What you must have first
- The verified image on the case store
- A custody record that begins at seizure, not at the bench
- Somewhere the original can be stored without further handling
What it produces for the case file
- The hash-chained audit trail and its sealed receipt
- The write-block verification with its stated coverage
What you do
- Work from the image, never the exhibitThe exhibit is read once. Everything after that runs against the copy.
recoveryantra recover --image E:\Case\Ex1\disk.E01 -o E:\Case\Ex1\Out --include-intact - Confirm the source is unchangedThe write-block check fingerprints deterministic regions of the source before and after, and reports the COVERAGE of what it checked rather than claiming the whole device is unchanged.
recoveryantra acquire -o E:\Case\Ex1 --write-block - Verify the audit trailThe trail is hash chained, so an edit, insertion or reorder is detectable. The manifest catches a trail cut short at the end, which the chain alone cannot see.
recoveryantra audit E:\Case\Ex1\Out\audit_trail.jsonl --manifest E:\Case\Ex1\Out\recovery_manifest.json
Why it matters
ASTM E3016 asks for the ways a result could be wrong to be identified and addressed. Stating the coverage of a verification, rather than asserting that nothing changed anywhere, is that principle applied.
Limits of this module
- The product records what IT did. Handling that happened outside it is not in the trail, which is why the physical custody record still matters.
- A verified chain shows the record is intact. It does not establish that the acquisition was lawful.
Hit one of these limits? The situation chooser names the product or the method that gets past each one, case by case.

What you must have first
- The verified image
- A written question the examination is meant to answer
- The case reference set consistently
What it produces for the case file
- The recovery manifest, with a hash and a source offset per item
- The search index and the terms run against it
What you do
- Recover what is on the volume, present and deletedThe forensic profile hashes every item and keeps a flat layout, so the output is evidence rather than a tidy delivery.
recoveryantra recover --image E:\Case\Ex1\disk.E01 -o E:\Case\Ex1\Out --include-intact --profile forensic - Check snapshots before concluding anything is absentA shadow copy frequently holds the file as it was before deletion. Absence from the live volume is not absence from the exhibit.
recoveryantra recover --image E:\Case\Ex1\disk.E01 --vss-list - Search rather than browseWhether an item was found deleted or present is frequently the point. The full-text half of the index is bounded on very large recoveries, and the product says when it is.
recoveryantra search E:\Case\Ex1\Out "<term>" --state deleted
Why it matters
ASTM E2916 exists so that two examiners mean the same thing by the same word. Recovered, carved, salvaged, deleted and present are distinct states in this product and they should stay distinct in the report.
Limits of this module
- An empty search result is not proof of absence where the index was bounded. Check what the product reported about the index.
- A file recovered by carving has no original name or folder, and saying otherwise misrepresents it.
Hit one of these limits? The situation chooser names the product or the method that gets past each one, case by case.

What you must have first
- The examination output
- The machine's clock setting and time zone
- More than one artefact type, where the question is about sequence
What it produces for the case file
- The unfiltered timeline, kept alongside the extract used in the report
- The structured memory output and the symbol file it was produced with
What you do
- Build the full timeline before filtering itNarrowing first hides the context that makes a sequence interpretable.
recoveryantra timeline E:\Case\Ex1\Out --out E:\Case\Ex1\timeline.csv - Bound it to the period in questionAn unbounded timeline from a busy machine is too large to read.
recoveryantra timeline E:\Case\Ex1\Out --start <iso> --end <iso> --out E:\Case\Ex1\window.csv - Analyse memory where it was capturedIdentify the kernel with memory info first, then supply the symbols for that EXACT build before reporting structured findings.
recoveryantra memory run E:\Case\Ex1\memory.raw --plugin pslist --symbols <symbols-dir> --out E:\Case\Ex1\mem.json
Why it matters
Error mitigation under ASTM E3016 means naming how the conclusion could be wrong. Timestamps can be altered, artefacts are cleared by routine maintenance, and a single artefact is weaker than two that agree. Corroborate, then say what you corroborated with.
Limits of this module
- Structured memory findings produced without a matching symbol file are not reliable and must not be reported as verified.
- Execution artefacts record that a program ran, not who was at the keyboard.
- A capped listing is a sample. It must never be quoted as a total.
Hit one of these limits? The situation chooser names the product or the method that gets past each one, case by case.

What you must have first
- The manifest, the audit trail and the analysis output
- The question the examination was asked to answer
- A clear separation between what was observed and what is inferred
What it produces for the case file
- The report in PDF, DOCX and HTML
- The JSON evidence bundle and the CSV list
- The verified audit trail and sealed manifest receipt
What you do
- Generate the report with the recoveryThe forensic report style carries the volume map, per-file state and the hashes; the summary style is for commercial work and carries neither.
recoveryantra recover --image E:\Case\Ex1\disk.E01 -o E:\Case\Ex1\Out --profile forensic --report pdf,docx,html - Verify the trail before disclosureRun at the close of the case and again before the report leaves.
recoveryantra audit E:\Case\Ex1\Out\audit_trail.jsonl --manifest E:\Case\Ex1\Out\recovery_manifest.json - Export the findings in a tool-agnostic formA structured JSON bundle and a flat CSV are produced alongside the report, so the receiving side is not obliged to use this product to read the findings.
recoveryantra search E:\Case\Ex1\Out "<term>" --limit 1000
Why it matters
FRE 702 asks for reliable methods reliably applied. A report that carries the method, the tool version, the per-item hashes and the source offset of each item lets a reviewer check the application, not only accept the conclusion.
Limits of this module
- The product produces the documents. Whether a given court or regulator accepts a given format is their decision, not a property of the software, and no report should imply otherwise.
- Anything the product could not verify is labelled unverified, and that label belongs in the report rather than being edited out.
Hit one of these limits? The situation chooser names the product or the method that gets past each one, case by case.

What you must have first
- Written confirmation that the deliverable has been accepted
- The organisation's retention policy
- The drive's own serial number, for anything being erased
What it produces for the case file
- The signed erasure certificate, stating the level ACHIEVED
- The disposal audit trail
What you do
- Sanitise the working copy once the job is acceptedOne pass. NIST SP 800-88r1 is explicit that one is sufficient on modern media; the three-pass ritual is withdrawn folklore.
recoveryantra wipe E:\Jobs\<ref>\work - Sanitise retired media and certify itZero fill, because a zeroed drive can be PROVEN clean by reading it back, then verified with the full recovery engine, then certified.
recoveryantra erase <device> --confirm <serial> --out E:\Disposal --examiner "<name>" - Reach Purge on flashThe controller clears remapped and spare blocks that a host overwrite cannot address.
recoveryantra erase <device> --confirm <serial> --firmware --out E:\Disposal --examiner "<name>"
Why it matters
The certificate's value is the verification behind it: the same engine sold to recover data is run against the erased drive, and the wipe is reported successful only if that engine finds nothing.
Limits of this module
- No software reaches the Destroy level defined by the standard; that requires physical destruction.
- Where a flash controller does not expose the spare area, the certificate says the spare and remapped blocks are not guaranteed cleared.
- On flash and copy-on-write file systems, overwriting a folder does not reach every copy, and the limits are stated on every run.
Hit one of these limits? The situation chooser names the product or the method that gets past each one, case by case.