Digital Forensics Solutions

Collect. Preserve. Prosecute.

Equipment and software for every stage of the forensic process, from seizure at the scene to court-ready evidence in the lab.

The Operational Context

The caseload has changed. The window hasn't.

20+
hours, average time examiners spend reviewing evidence per case
Source: Magnet Forensics State of DFIR, 2025

Forensic teams are handling more cases, with more data per case, across more device types than ever. The legal and technical window for acquiring that evidence keeps shrinking. Devices encrypt on timeout. Data syncs to the cloud. Remote wipe commands travel at the speed of a mobile connection.

The choice of equipment, procedures and software used at the point of seizure, during transport to the lab, and in the lab, will determine how much of the evidence from the seized device makes it to, and is upheld by, the courts.

The Forensic Reality

Six operational pressures that shape every case.

If you’ve worked in digital forensics in the last twelve months, you’ve likely experienced these pressures.

Remote Wipe
A suspect or accomplice can wipe a seized device long before it reaches the lab. Without immediate RF isolation at point of seizure, the evidence is gone before the examiner sees it.
Device Lockout & Encryption
Modern devices enforce aggressive lockout policies. Time-based, attempt-based, passcode-triggered. A device that goes cold makes extraction exponentially harder.
Battery Death
If the device shuts down before extraction, you lose volatile memory, unlock state, and can trigger full-disk encryption on reboot. Maintaining device charge during signal isolation is essential.
Chain of Custody
Defence counsel scrutinises chain-of-custody gaps. Any question about whether a device was accessed, modified, or exposed to network signals can undermine admissibility.
Volume & Backlog
Examiners manage six to ten concurrent cases and twenty-plus hours per case on review. Manual correlation across dozens of data sources is no longer sustainable at scale.
Field vs Lab Constraints
Device seizure occurs at the crime scene.Equipment has to be portable, durable, and immediately deployable without sacrificing forensic integrity.

The Forensic Workflow

From seizure to court-ready evidence.

Seven stages, seven operational fields. Each one has its own pressures, requires specific equipment, and has its own bar for producing court-ready evidence. The seven stages are covered below, along with the Faraday and digital forensic equipment we recommend.

Field Operations
01 Seizure Isolate the device
Forensic officer placing seized device into a Mission Darkness NeoLok Faraday bag at scene

The first minute is critical. A device that's still connected to a network at the point of seizure can be wiped, tracked, or tampered with before it reaches transport. Immediate RF isolation at the scene is the only defence.

What we recommend: Mission Darkness NeoLok Faraday bags for Law Enforcement and forensic deployment. Patented magnetic closure, serialised for chain of custody, tested to IEEE 299-2006 and MIL-STD-188-125. OffGrid Faraday bags where the operational context calls for a low-profile carry.

02 Transport Maintain signal isolation
Mission Darkness NeoLok bags in transit configuration with chain-of-custody seal

Chain of custody starts the moment the Faraday bag is sealed. RF isolation must be maintained during transport, handoffs, and storage. Sometimes for hours, sometimes for days. A bag that tests well in the lab but degrades in the field has failed.

What we recommend: Mission Darkness NeoLok window and non-window bags for examiner handoff with visible device status. Faraday MOLLE pouches for tactical transport.

03 Power Charge while shielded
Mission Darkness Charge & Shield bag with USB-C power feed maintaining device charge through Faraday isolation

A device that dies in transit loses volatile memory and may trigger full-disk encryption on reboot. Keeping the device charged while maintaining signal isolation is essential in the field-to-lab chain.

What we recommend: Mission Darkness Charge & Shield Faraday bags for phone and tablet forensic workflows that plug into evidence locker and lab extraction systems. OffGrid Phase Filter for laptops and any context where USB-C and toggle-switchable data mode matter more than cabinet integration.

04 Store Custody before queue
Mission Darkness Blocker Locker multi-device shielded storage cabinet

A device arrives at the lab and goes into custody, sometimes for hours, days or weeks. In that time, devices must remain charged and shielded while waiting in queue for password cracking and data extraction. The use of purpose-made Faraday evidence lockers is integral during this stage.

What we recommend: Mission Darkness Blocker Locker. Multi-device RF shielded storage with continuous power and individual device isolation. Built for the period between intake and active examination where maintaining chain of custody is essential.

Lab Analysis
05 Examine Shielded workspace
Forensic examiner working through Mission Darkness BlockBox glove ports inside RF-shielded enclosure

Hands-on device interaction and preliminary triage should happen in a controlled RF environment. In the lab, that's a purpose-built Faraday examination enclosure with integrated glove ports. In the field, it's a Rapid Deploy Faraday tent that travels to the scene, giving the examiner the same RF-controlled workspace wherever the case takes them.

What we recommend: Mission Darkness BlockBox range for RF-shielded examination across lab and field-lab configurations, including glove-port workflows for bench extraction. Rapid Deploy Tents for on-scene analysis where the workspace has to travel.

06 Extract Forensic acquisition
Belkasoft X forensic extraction interface showing multi-source acquisition view

Forensic acquisition is no longer one method on one device. Mobile, computer, RAM, cloud, vehicle, drone, IoT. Each case pulls from multiple sources and the tool has to match the target. Every extraction step needs to be logged, hash-verified, and exportable in a format NZ courts accept.

What we recommend: Belkasoft X for full-platform acquisition across mobile, computer, RAM, cloud, and drone sources. Detego Ballistic Imager for field-deployable imaging at up to eight times industry-standard speed. See our forensic software range →

07 Analyse Court-ready reporting
Forensic analysis network graph showing entity relationships across multiple data sources

Data extraction is the start. Analysis is where connections surface between suspects, devices, locations, and cases. Manual correlation across dozens of data sources no longer scales. AI-assisted analysis keeps the workload sustainable and the audit trail intact.

What we recommend: Belkasoft X with BelkaGPT for offline AI-assisted investigation. Detego Analyse AI+ for automated categorisation and court-ready reporting. xBit for case and lab management across concurrent investigations. See our forensic software range →

Field-grade isolation

The Faraday bag is the first line of defence.

Every forensic chain of custody starts with a Faraday bag. Mission Darkness covers the Law Enforcement-grade and tactical operational range; OffGrid covers the premium and laptop range. Both are world leaders in their Faraday products.

Mission Darkness NeoLok Faraday bag with magnetic closure and serialised label
Mission Darkness Law Enforcement
NeoLok Faraday Bags

Patented magnetic neodymium closure with with unique serial number for chain-of-custody. Window and non-window models. Certified to IEEE 299-2006 and MIL-STD-188-125-2. The forensic standard at the point of seizure.

Use cases: Seizure, transport. Phones, tablets, small devices.

Mission Darkness Dry Shield MOLLE Faraday pouch attached to tactical vest
Mission Darkness Tactical
Dry Shield MOLLE

MOLLE-attachable Faraday isolation built for tactical carry. Waterproof ballistic nylon. Unique serial number. For first responders, tactical units, and field forensic teams that need shielded capacity on a vest or pack. Certified to IEEE 299-2006 and MIL-STD-188-125-2.

Use case: Tactical seizure, on-person carry. Phones, radios, GPS.

Mission Darkness Charge & Shield Faraday bag with integrated USB-C power feed
Mission Darkness Power-shielded
Charge & Shield

Faraday bags with integrated USB-C power feed for devices that need to stay charged and shielded from point of seizure to the laboratory. Window and non-window models available. Unique serial number. Plugs directly into Mission Darkness evidence locker and lab extraction systems. Maintains charge without breaking the RF seal. Certified to IEEE 299-2006 and MIL-STD-188-125-2.

Use case: Transit, custody. Devices that must remain powered for forensic status preservation.

OffGrid Phase Filter Faraday bag for laptops with USB-C toggle data mode
OffGrid Premium
Phase Filter Faraday Bag

Premium Vega Wrap construction with toggle-switchable USB-C data mode. Allows charging and USB 2.0 data throughput on the same sealed connection. For phones, tablets and laptops. Certified to IEEE 299-2006 and MIL-STD-188-125-2.

Use case: Device forensics, executive travel, USB-C contexts.

Field and Lab Hardware

Beyond the Faraday bag.

Faraday bags solve the RF signal isolation problem at the point of seizure. A complete forensic operation needs more: shielded storage during extended processing, examination enclosures for bench work, and specialist hardware for the operational problems beyond isolation.

The Custodi product range covers the full forensic hardware lifecycle across two authorised brands offering military-grade equipment – Mission Darkness for forensic-grade Law Enforcement and examination hardware; OffGrid for premium design and Phase Filter charging technology.

Mission Darkness storage and processing cabinets: Blocker Locker, Crack Cabinet, Charge Cabinet

Shielded Storage & Data Processing

Shielded and unshielded cabinets for lab workflows. The Blocker Locker holds devices in Faraday isolation during the queue between intake and examination; the Crack Cabinet supports password attack runs; the Charge Cabinet keeps devices powered.
View storage range →
Mission Darkness BlockBox XL forensic examination enclosure

Forensic Investigation

Lab and field-based enclosures with shielded Faraday glove ports, AC power and I/O ports for hands-on device work in a completely RF isolated environment. An optional mounted camera to record evidence recovery in real time.
View investigation range →
Mission Darkness Faraday Drone Shield in field operations

Drone Forensics

Shielded Faraday isolation for consumer and professional drones. Aerial imagery, GPS logs, flight path records, and pilot account data preserved from the moment of recovery. Then field-based forensic investigation enclosure for UAV examination and data retrieval.
View drone range →

Build A Complete Forensic Capability.

Every product in the Custodi forensics hardware range is part of an integrated system. A single Faraday bag solves one problem. A fully specified lab (which includes bags for seizure, transport, charge-and-shield, and Phase Filter, shielded storage, examination enclosures, and specialised covers and tents) solves the entire workflow.

Forensic Software

The forensic software lifecycle.

Modern investigations have outgrown manual data extraction and analysis. A single case can include dozens of evidence sources and many terabytes of data. The forensic software lifecycle divides into three phases: acquisition, analysis, and workflow.

Acquisition and analysis both now demand AI-assisted tools. The software platforms Custodi offers can run offline on your hardware, with auditable processing and cited sources for every output. Offline, auditable, and source-cited. Versus online, opaque, and unverifiable.

We currently offer four forensic software platforms in New Zealand. Belkasoft with its BelkaGPT AI extension is the lab standard for full-spectrum extraction and analysis. Detego with its Analyse AI+ extension brings field-first acquisition and rapid triage. MSAB’s XRY and XAMN are the mobile-first standard, with Unify coordinating cases across distributed teams. xBit is the workflow layer that holds the whole lifecycle together.

Phase 01 · Acquisition Extracting the data, forensically intact

Belkasoft X

The full-spectrum acquisition platform. Supports every major method. Logical, filesystem, physical, JTAG, chip-off, and cloud. Across mobile devices, computers, RAM captures, drone telemetry, and IoT sources. 1,500+ artifact types covering the apps and operating systems forensic teams encounter daily. Every extraction logged, hash-verified, and exportable in court-accepted formats.

Detego

Field-deployable acquisition built for speed at the point of seizure. Ballistic Imager holds the current world record for forensic imaging speed at 1TB in 4 minutes 34 seconds. Field Triage runs from USB with no installation, allowing non-specialist personnel to conduct on-scene acquisition without compromising chain of custody.

MSAB XRY

Mobile device extraction trusted by law enforcement in over 100 countries. Logical, physical, and file-system methods across current-generation smartphones, tablets, drones, and legacy handsets. Extraction from encrypted devices via chip-off and JTAG. Every extraction hash-verified and logged for chain of custody.

Phase 02 · Interrogation Making sense of what the data contains
By Belkasoft

BelkaGPT

The forensic AI that doesn't leave the workstation. A fully offline large language model purpose-built for digital forensics. Query case data in natural language. Every answer cites its source artifacts. No case data crosses the network. For agencies where cloud-based AI is a non-starter on privacy, legal, or chain-of-custody grounds, BelkaGPT is the practical alternative.

By Detego

Analyse AI+

Automated content analysis included at no additional cost with Detego's extraction tools. Face recognition, multi-language OCR across 100+ languages, semantic search, AI-generated content detection, object detection, password decryption, steganography detection, and PhotoDNA matching for CSAM identification. Speed without admissibility isn't a forensic tool. Every output carries a full audit trail.

MSAB XAMN

The analysis layer for MSAB extractions. Presents recovered mobile evidence as visual timelines, chat thread reconstructions, geolocation mapping, and structured reports. Filter, tag, and pivot across artifacts without leaving the tool. Court-ready export formats for cross-examination and disclosure.

Phase 03 · Workflow & Presentation Managing the case from custody to court

xBit

The layer that holds the case together. Case-level audit log, chain-of-custody record, licence management, and workflow state across concurrent investigations. Built by forensic examiners for forensic workflows. Makes every extraction and analysis above it court-defensible.

MSAB Unify

Case-file coordination across distributed forensic teams. Assigns examiners, tracks evidence lifecycle, and centralises audit trails across MSAB extractions and analysis. Standardises workflow between regional and central labs. Gives auditors and courts a single defensible record.

Standards and Frameworks

Specified to the standards your evidence will be tested against.

Digital evidence in New Zealand is judged under the Evidence Act 2006 and the Search and Surveillance Act 2012, within the procedural safeguards of the Bill of Rights Act 1990 and the Privacy Act 2020. Operational practice draws on ACPO, ISO/IEC 27037, NIST, and SWGDE.

Custodi supplies products that meet this framework. Our Faraday products and hardware are independently certified by Keystone Compliance Laboratories in the USA to IEEE 299-2006 and MIL-STD-188-125-2 .

NZ Legal Framework
  • Evidence Act 2006
  • Search and Surveillance Act 2012
  • Bill of Rights Act 1990
  • Privacy Act 2020
International Methodology
  • ACPO Good Practice Guide
  • ISO/IEC 27037:2012
  • NIST SP 800-86 | NIST IR 8387
  • SWGDE Best Practices
FARADAY Engineering & Shielding
  • IEEE 299-2006
  • MIL-STD-188-125-2
  • Keystone Compliance Laboratory
  • Verified Faraday fabrics: TitanRF | Vega Wrap

Collect. Preserve. Prosecute.

Custodi is the exclusive NZ channel for Mission Darkness and OffGrid, and authorised reseller for Belkasoft, Detego, MSAB, and xBit. Field-to-lab equipment across the range: Faraday bags and analysis enclosures, shielded forensic tents, extraction and analysis platforms, case management for chain of custody, and Belkasoft training by a Certified Instructor.

Specified for the standards your evidence will be tested against.

Trusted by NZ Government NZ Police · NZDF · NZ Customs · MFAT · DIA · Parliamentary Service
Authorised Channel Mission Darkness · Belkasoft · Detego · MSAB · OffGrid