Semantics 21 Asks The Uncomfortable Question Every Review Team Should Be Asking

The Files You Cannot See Cannot Be Investigated

Do you check whether your tool shows you everything or do you just assume it does?

That assumption is now too important to leave untested. Modern investigations are not short of digital material. They are short of reliable visibility inside that material. Images, videos, exports, metadata, corrupt files, damaged media and unsupported formats can all sit inside the same case environment.

The operational question is no longer just ‘Can the tool process the evidence?’ It is now ‘Can investigators see what the tool has left out?’

A reported media count is not proof that the full dataset is visible. A processed case is not proof that every item has reached the investigator. A clean review queue is not proof that nothing has been excluded from view.

When did it become acceptable for a forensic tool to list excluded files once at the start of a case, then allow those files to disappear from the investigation entirely? That is not a technical detail, that is an evidence visibility problem.


Get The Latest DFIR News

The monthly Forensic Focus newsletter, plus webinar invitations and occasional research surveys.

Unsubscribe or change what you receive at any time. We respect your privacy: read our privacy policy.


Assumption Is Not Verification

Investigators are trained to test, challenge and verify. The same standard should apply to the tools used to review evidence.

If a tool imports fewer files than the export contains, the investigator needs to know. If files are excluded because they are corrupt, damaged, unsupported or difficult to process, the investigator needs to know. If excluded material is recorded only in a log and then removed from the working review view, the investigator needs to know.

Not because every missing file will be important but because nobody should have to assume it is not.

Partial visibility creates false confidence. It allows a team to believe they are reviewing the case when they may only be reviewing the portion their tool has made visible. The problem is not only missing data, the problem is not knowing what is missing.

Difficult Files Still Matter

There is a reason we use headlights in the dark.

A corrupt file is not automatically worthless. A damaged image may still carry EXIF metadata. A broken video may still contain dates, device information, naming patterns or location indicators. A file that cannot be fully opened may still help explain where material came from, when it was created or how it moved through a device or dataset. Why throw that away?

Why should difficult material become invisible simply because it is harder to process?

If material never reaches the investigator, it cannot be assessed, prioritised, explained or challenged. That should make every team uncomfortable.

Run Both Tools on the Same Dataset

There is a simple way to start.

Run your current tool against the same dataset as S21 VisionX. Compare the outputs. Check the number of files imported.

Compare that number with the JSON export. Look for excluded media, corrupt files, damaged material and unsupported content. Then ask whether those files remain visible to the investigator or disappear after initial processing.

This is not a theoretical exercise. It is a practical visibility check. If both tools show the same material, you have evidence for confidence. If they do not, you have a question worth answering.

S21 VisionX Keeps Difficult Material in View

S21 VisionX is built for investigator-led visual evidence review at scale. It supports prioritisation, grouping, similarity and review workflows while keeping professional judgement with trained investigators.

But the verification issue starts even earlier. S21 VisionX displays all files in a case – no matter how corrupt, damaged or difficult they are to process.

Even where content cannot be fully reviewed, the file remains visible to the investigator. That matters because difficult files can still carry metadata, context and investigative relevance.

S21 VisionX does not remove professional judgement. It strengthens the workflow around it by giving investigators a clearer view of what exists inside the case, including material that other review environments may move out of sight.

Interested in Checking Your Current Workflow? Worried Your Current Tool Is Missing Data?

Start with a simple comparison. Check whether your tool is importing the same number of files as your JSON export. If the numbers do not match, ask why.

Click here to email Semantics 21 and express your interest in S21 VisionX.

Leave a Comment