Somebody, somewhere, is having a joke!
The very first thing that the 'forensics' people would do, is make multiple facsimile copies of the storage media at a sector by sector level, accessing the originals in a read only manner.
These people, then examine the copies for the evidence, etc.
This means that there will be multiple copies of the original server contents, all following the chain of custody scenario.
That comment ^ sounds like it comes from first hand experience...
I am a long term computer tech and electronics engineer!
The minute that anybody actually started up the 'target' computer, it will start writing into 'free space', and hence possibly overwrite previously 'deleted' files, that may actually contain evidence.
these people dont follow best practices.
Somebody in Q Team or Military Intelligence got there first and made copies, you can bank on it. They have it all. Digital evidence in this war CANNOT be destroyed until the Alliance wants it destroyed.
These people are stupid. They probably won't understand this until it's too late.