<?xml version="1.0" encoding="UTF-8"?>
<certificate format="e-Dex-certificate" version="1.0">
  <template>
    <id>forensic-examination</id>
    <name>Digital Forensic Examination Certificate</name>
    <category>Digital Forensics</category>
    <jurisdiction>Global</jurisdiction>
  </template>
  <integrity algorithm="SHA-256" sealedLineCount="29">
    <hash>9f7b8436e44928eab6acbb4f34550d9212bc047f5bbe3bcd8ecd90023ac01afb</hash>
    <verification>Recompute SHA-256 over each sealedContent line followed by a newline (UTF-8); the result must equal the stated hash.</verification>
  </integrity>
  <signing signed="false" timestamped="false"/>
  <generatedAt>fixture</generatedAt>
  <sealedContent>
    <line>DIGITAL FORENSIC EXAMINATION CERTIFICATE</line>
    <line>Template: forensic-examination</line>
    <line></line>
    <line>Case: Seized laptop examination (CASE-FEXAM)</line>
    <line>CaseNumber: CC/2026/0042</line>
    <line>FIR: FIR-2026-77</line>
    <line>Court: Court of the Chief Judicial Magistrate, Pune</line>
    <line>Analyst: Pallavi Pawar</line>
    <line>Organisation: Innovativa SoftTech</line>
    <line>exam.methodology: Write-blocked acquisition; keyword and timeline analysis; manual review of recovered artifacts.</line>
    <line>exam.tools: e-Dex 1.4.0, Autopsy 4.21, hardware write-blocker</line>
    <line>exam.findings: Examination of the seized hard disk recovered 14 deleted documents relevant to the matter. The artifact timestamps are consistent with the period under investigation. No evidence of anti-forensic wiping was observed. The recovered items and their cryptographic hashes are listed in the annexure to this certificate.</line>
    <line>SOURCE_DEVICE</line>
    <line>  DeviceName=Seized laptop HDD</line>
    <line>  DeviceType=Hard Disk Drive</line>
    <line>  DeviceMake=Western Digital</line>
    <line>  DeviceModel=WD10EZEX</line>
    <line>  DeviceSerial=WD-WX21A1234567</line>
    <line>  DeviceOs=Windows 11 Pro</line>
    <line>  DeviceOwnership=Accused</line>
    <line>ANNEXURE</line>
    <line>  1. evidence-1.dd | 53477376 | Verified</line>
    <line>     SHA-256=874e9c3ea2b3c4dda2b3c4e5a2b3c4eda2b3c4f5a2b3c4fda2b3c505a2b3c50d</line>
    <line>  2. evidence-2.dd | 54525952 | Verified</line>
    <line>     SHA-256=913213d9a3b4c5dea3b4c5e6a3b4c5eea3b4c5f6a3b4c5fea3b4c606a3b4c60e</line>
    <line>  3. evidence-3.dd | 55574528 | Verified</line>
    <line>     SHA-256=9b158b74a4b5c6dfa4b5c6e7a4b5c6efa4b5c6f7a4b5c6ffa4b5c707a4b5c70f</line>
    <line>VERIFICATION verified=3 failed=0 errors=0</line>
    <line>DECLARATION I certify that I conducted the digital forensic examination described in this certificate, that the methodology and tools recorded above were used, that the cryptographic hash values of the examined items are reproduced in the annexure, and that the findings stated above are a true and accurate record of the results of that examination to the best of my knowledge, information and belief.</line>
  </sealedContent>
</certificate>
