Digital Forensics

How to Prove a Digital Document Was Altered: PDF Metadata Examination in Kenya

PDF Metadata Examination Kenya · Digital & Document Forensics The Contract Says 2019. The File Disagrees. Every digital document carries a second, invisible record of its own history — one that isn’t written by whoever typed the visible text. PDF metadata examination in Kenya is how that hidden record gets read, and how backdated contracts and forged agreements get caught. 3Independent metadata sources per document type 106AEvidence Act standard for electronic records 0Alterations made during examination In short A digital document’s visible content and its actual history are recorded separately. PDF properties, Word’s internal revision structure, and a photograph’s EXIF data all capture when a file was truly created, edited, and saved — independent of whatever date appears in the printed or displayed text. PDF metadata examination in Kenya compares these hidden records against the document’s claimed date to establish whether a contract, agreement, or letter is genuine. Why a Digital Document Can’t Fully Hide Its Own History A paper document only shows what’s on the page. A digital one carries a second record most people never think to look at — created automatically by the software that produced it, without the author’s involvement or awareness. This is the foundation of PDF metadata examination in Kenya: comparing what a document claims about itself against what the file format was actually built to record. This matters because the most common way a fabricated document gets caught isn’t a spelling mistake or an inconsistent signature — it’s a mismatch between the story the document tells and the story its own file structure tells. Three sources carry most of that story: PDF properties, Word’s internal revision data, and EXIF metadata in photographed signature pages. 📄 PDF Properties & Metadata Every PDF embeds a Document Information Dictionary and often XMP metadata recording creation software, creation date, and modification history — set by the computer, not the author. 📝 Word Revision History A .docx file is a compressed archive of XML parts. Author names, save timestamps, and sometimes prior revisions can persist inside that structure long after visible track changes are cleared. 📷 EXIF Data Photos of signed signature pages — sent over WhatsApp or email — often carry a capture timestamp, device model, and sometimes GPS coordinates, independent of anything written on the page itself. “You can retype a date. You cannot retype the moment your computer says the file was actually born.” PDF Properties: What the Document Information Dictionary Reveals Open the properties panel of almost any PDF and you’ll find a small set of fields most people ignore: Author, Producer, CreationDate, ModDate, and often the specific software version used to generate it. These fields are written automatically at the moment of export or save — a contract “created” using a version of Adobe Acrobat or Microsoft Word that didn’t exist yet at the claimed contract date is, on its own, close to conclusive. Beyond the visible properties panel, many PDFs also carry XMP metadata — a more detailed, XML-based record embedded in the file that can include edit history, prior filenames, and the specific application and operating system used at each save. Where a PDF has gone through multiple saves or exports, XMP metadata can preserve a trail of those events even after the visible properties panel has been manually edited to show something else. Anatomy of a Backdated PDF What the Document Claims vs. What Its Properties Actually Record A simplified, illustrative property panel — annotated the way an examiner reads it during a PDF metadata examination in Kenya. Document text states:“Executed this 4th day of March, 2019” CreationDate:2026-05-14 11:42:07POSTDATES CLAIM ModDate:2026-05-14 11:47:52SAME-DAY EDIT WINDOW Producer:Microsoft® Word for Microsoft 365VERSION DID NOT EXIST IN 2019 Author:DESKTOP-6XJ2P\\userDEVICE NAME UNRELATED TO SIGNATORY XMP Edit History:2 prior save events detectedCONTRADICTS “ORIGINAL SCAN” CLAIM FAIL Directly contradicts the document’s claimed history WARN Inconsistent, needs corroboration PASS Consistent with genuine timeline Word Revision History: What Survives “Accept All Changes” A .docx file is not a single block of text — it’s a ZIP archive containing multiple XML files that separately describe the document’s content, formatting, comments, and revision data. Clicking “Accept All Changes” removes the visible track-changes markup from the reading view, but it doesn’t always purge every trace of that history from the underlying file structure, especially where a document has been saved rather than freshly exported as a clean copy. Examiners look specifically at the document’s internal author list — every account name that has ever edited the file, in what’s sometimes a longer list than the document’s visible signatories would suggest — alongside embedded save timestamps and, in some cases, remnants of deleted comments or prior paragraph versions. A contract whose internal author history includes a name entirely unconnected to either party, or whose earliest recorded edit postdates the agreement’s claimed signing date, raises exactly the kind of question a court or opposing counsel needs answered. EXIF Data: When the “Original Signed Copy” Is Just a Photo An enormous number of disputed agreements in Kenya don’t arrive as clean PDFs at all — they arrive as a photograph of a signed page, taken on a phone and sent over WhatsApp or email. That photograph carries its own metadata, called EXIF (Exchangeable Image File Format) data, which can include the exact date and time the photo was taken, the camera or phone model used, and — where location services were enabled — GPS coordinates for where the photo was captured. This becomes significant when a photographed “original” signature page is claimed to have been signed at one time and place, but its EXIF capture timestamp — or the compression pattern typical of a specific messaging app’s re-encoding — tells a different story. Even where an image has been forwarded and re-compressed multiple times, forensic examination can often still establish the file lineage and, where original EXIF data survives, the true capture window. Backdated Contracts: Reading the Three Sources Together The strongest findings rarely rest on a single metadata field — they come from

How to Prove a Digital Document Was Altered: PDF Metadata Examination in Kenya Read More »

Business Email Compromise Kenya: How Digital Forensics Uncovers Fake Invoices & CEO Fraud

Business Email Compromise Kenya · Digital Forensics The Wire Instruction Came From Your Supplier. Except It Didn’t. Business Email Compromise in Kenya rarely looks like a hack. It looks like an ordinary email, from an ordinary sender, asking for something an ordinary sender would ask for — until forensic analysis of the header tells a different story. 3Authentication checks every header must pass 90 DaysTypical M365 audit log window before evidence degrades 106AEvidence Act standard for email admissibility In short Business Email Compromise (BEC) in Kenya is proven, not assumed. Digital forensic examiners recover and analyze the full raw email header — not just what appears on screen — to establish whether a message was spoofed from outside the organisation or sent from a genuinely compromised Microsoft 365 mailbox. That distinction determines who is liable, what a bank can act on, and what a court will accept as evidence. Banks & Financial Institutions Corporates & Finance Teams Law Firms & Litigators Why Business Email Compromise Is Kenya’s Costliest Quiet Fraud Business Email Compromise doesn’t trip antivirus software or trigger a firewall alert. It exploits trust between two humans who already do business with each other — a supplier and a client, a CFO and a bookkeeper, a law firm and its escrow client. That’s what makes Business Email Compromise in Kenya so difficult for finance teams to catch in the moment, and why forensic reconstruction after the fact is so often the only route back to the truth — and to any recoverable funds. Three patterns account for most of the BEC matters instructed to forensic examiners in Kenya: 🧾 Fake Invoice Fraud A genuine supplier relationship is hijacked mid-transaction. New “updated” bank details arrive on an invoice that looks identical to every previous one — because the template, logo and reference numbers were copied from a real, intercepted email. 🧑‍💼 CEO Fraud An urgent instruction, apparently from a senior executive, requests an unusual same-day transfer — deliberately timed for when the real executive is travelling or unreachable to verify by phone. 💰 Payroll & Account Diversion HR or payroll receives a request, apparently from an employee, to update salary bank details — quietly redirecting future payroll to an account the employee never opened. “The logo is real. The signature block is real. The one thing that isn’t real is the path the email actually travelled to reach the inbox.” Spoofing vs. Compromise: Two Different Crimes, Two Different Evidence Trails Every BEC case forensically resolves into one of two categories, and the distinction changes everything about liability and recovery: Email Spoofing The attacker never accessed the real account. Instead, they forge the “From” name and address so the message displays as if it came from a trusted sender, while it was actually sent through an entirely different mail server. Spoofing leaves its fingerprints in authentication results and the header’s server path — the account itself was never touched. Account Compromise Here, the attacker genuinely logged into the real mailbox, usually via a phished password or a stolen session token. The email genuinely came from the real account — the evidence trail instead lives in sign-in logs, new mailbox rules, and permission changes inside Microsoft 365, not in the header’s authentication fields. Header Analysis: Reading What the Inbox Doesn’t Show You Every email carries a raw header most people never see — a technical record of every server it passed through and every authentication check it was subjected to. This is the primary forensic artifact in a spoofing investigation. Anatomy of a Spoofed Header What the Reader Sees vs. What the Header Actually Records A simplified, illustrative header — annotated the way an examiner reads it during a Business Email Compromise investigation in Kenya. From:Finance Director <[email protected]> Reply-To:[email protected] MISMATCH Return-Path:[email protected] DOMAIN Received:from unlisted-smtp-relay (unverified) by …UNRECOGNISED SERVER SPF:softfailFAIL DKIM:noneFAIL DMARC:fail, p=rejectFAIL FAIL Authentication check failed — strong spoofing indicator WARN Inconsistent but not conclusive alone PASS Consistent with genuine sender Three fields do most of the work in a spoofing determination. SPF (Sender Policy Framework) checks whether the sending server is authorised to send on behalf of that domain. DKIM (DomainKeys Identified Mail) verifies a cryptographic signature tied to the domain, which a spoofer cannot forge without access to the domain’s private key. DMARC tells receiving servers what to do when SPF or DKIM fail — and its own pass/fail result, together with the alignment between the visible “From” and the technical “Return-Path,” is often the single clearest indicator an examiner presents to a court or a bank’s fraud team. A subtly misspelled domain — an extra letter, a swapped character, a different top-level domain — is one of the most common spoofing techniques precisely because it survives a quick visual read. Forensic analysis compares every domain reference in the header character-by-character, which is where these near-identical impersonations are caught. Microsoft 365 Investigations: What to Pull When the Mailbox Itself Was Compromised When the evidence points to genuine account compromise rather than spoofing, the investigation moves from the header into Microsoft 365’s own audit and security infrastructure. AUDIT LOG Unified Audit Log: records mailbox access, file access, and administrative actions — the primary timeline for establishing exactly when compromise occurred and what the attacker did with access. INBOX RULES Malicious forwarding rules: attackers frequently create a hidden rule that silently forwards or deletes specific incoming emails — commonly used to intercept invoice replies and hide them from the real account owner. SIGN-IN LOGS Azure AD sign-in records: reveal login location, device, and “impossible travel” patterns — a login from Nairobi followed minutes later by one from an unrelated country is a strong compromise indicator. PERMISSIONS Mailbox delegate & permission changes: attackers sometimes grant themselves or another mailbox ongoing access rather than repeatedly logging in — a change examiners specifically check for. Where This Sits in Kenyan Law Computer Misuse & Cybercrimes Act 2018: unauthorised access to a mailbox and forgery of an electronic message both form distinct criminal grounds under

Business Email Compromise Kenya: How Digital Forensics Uncovers Fake Invoices & CEO Fraud Read More »

Computer & Hard Drive Forensics in Kenya: How Forensic Imaging Proves Backdated Documents and Data Theft

Digital & Cyber Forensics · Kenya The File Says January. The Drive Says Otherwise. Anyone can change the date on a document. Almost no one can change what the file system quietly recorded underneath it. That gap is where computer and hard drive forensics does its work. 4Timestamps cross-examined per file 0Alterations made to the original drive SHA-256Hash standard verifying image integrity In short Computer and hard drive forensics never examines the original device. A write-blocked, hash-verified image is captured first, and every finding — deleted files, backdated documents, exfiltrated data — is drawn from that image. This is what allows the original to be handed straight back to its owner while the analysis proceeds, and what makes the findings defensible if the opposing side challenges how the evidence was handled. Why the Original Drive Is Never Touched The most common way digital evidence gets thrown out in a Kenyan court isn’t a bad finding — it’s a bad process. If an examiner works directly on the original computer, opposing counsel only needs to raise one question: how do we know nothing was altered? Forensic imaging exists to remove that question entirely. A write-blocker is a hardware device that physically permits data to be read off a drive while making it impossible to write anything back to it — not even an operating system’s routine background writes. Once attached, the examiner captures a complete, bit-for-bit copy of the drive, including deleted and unallocated space the owner can no longer see through normal use. All analysis happens on that copy. “You cannot argue with a hash value. Either the image matches the original, or it doesn’t — there is no middle ground for a court to weigh.” The Imaging Chain Evidence Integrity Process Five Steps Before Analysis Even Begins This sequence is what a chain-of-custody log actually documents — and what an opposing expert will look for gaps in first. 1 Write-Blocker Attached The drive is connected through hardware that permits reading only — no write commands can reach it. 2 Bit-for-Bit Image Captured Every sector is copied, including deleted and unallocated space — not just visible files. 3 Hash Value Generated A SHA-256 fingerprint is calculated for the original and the image, immediately after capture. 4 Hash Verified Match Original and image hashes are compared — an exact match proves the copy is forensically identical. 5 Original Sealed & Returned The source drive is logged and returned to its owner. All further work happens only on the verified image. Proving a Backdated Document A document’s visible “created” date is something almost any user can edit or spoof. What’s far harder to falsify consistently is the constellation of timestamps the file system itself maintains — commonly referred to by examiners as MACE metadata. Reconstructing a genuine timeline means comparing all four against each other and against other artifacts on the drive: recent-file lists, print spool records, backup snapshots, and system event logs from around the claimed date. M Modified Last time the file’s content was changed A Accessed Last time the file was opened or read C Created When the file first appeared on this drive E Entry Modified Last change to the file’s own metadata record A document that was genuinely drafted on the claimed date will show these four timestamps in a pattern consistent with normal editing. A document that was written recently and then dated backward almost always shows an inconsistency somewhere in that pattern — a created date that postdates a modified date, for instance, or a file that was “created” in one location but whose surrounding system artifacts place it somewhere else entirely. Data Exfiltration: What an Employee’s Drive Actually Reveals When a departing employee is suspected of taking client lists, source code, or commercial records, the drive rarely has to be searched blindly — it already keeps a record of what left it. USB Removable device history: the registry retains a record of every USB drive ever connected, including serial numbers and the first and last time each was plugged in. RECENT Recently accessed files: shortcuts and jump lists reveal exactly which files were opened in the days before resignation, even if the files themselves were later deleted. CLOUD Sync and upload artifacts: local cache folders for cloud storage clients often retain evidence of what was uploaded, even after the account is logged out. DELETED Unallocated space recovery: deleting a file removes its directory entry, not the underlying data — recoverable until that space is overwritten by new files. Where This Sits in Kenyan Law Evidence Act (Cap. 80), ss. 106A–106C: the forensic image and its findings must meet the same “regular use, no unauthorised interference” standard as any other electronic record before a court will admit it. Computer Misuse & Cybercrimes Act 2018: unauthorised access to an employer’s system, or unauthorised copying of protected data, forms the criminal basis where exfiltration crosses into a prosecutable offence. Employment Act, 2007: forensic findings of exfiltration or policy breach frequently underpin the fairness of a summary dismissal, which is why documented, defensible process matters as much as the finding itself. Illustrative Matter · Nairobi · Corporate Instruction A Resignation Letter, Backdated by Eleven Days A departing finance manager produced a resignation letter dated to before a disputed transaction was authorised. Forensic imaging of the laptop showed the document’s file-system creation timestamp postdated the transaction by several days, while the visible “date” field in the document text had been manually altered. Recent-file artifacts further placed the document’s drafting session on a specific afternoon, corroborated by login records for that session. Timestamp inconsistency and drafting-session evidence documented for the client’s legal team ahead of tribunal proceedings. Frequently Asked Questions Does forensic imaging require shutting down or taking away the original computer? No. A write-blocked bit-for-bit image can usually be captured on-site, with the original device returned to service the same day. Every subsequent examination happens on the image, never the original — which is what keeps the original

Computer & Hard Drive Forensics in Kenya: How Forensic Imaging Proves Backdated Documents and Data Theft Read More »